Multiple Vendor Linux deliver 2.0.12 and below Buffer Overflow Vulnerabilities
BID:226
Info
Multiple Vendor Linux deliver 2.0.12 and below Buffer Overflow Vulnerabilities
| Bugtraq ID: | 226 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Jan 12 1998 12:00AM |
| Updated: | Jan 12 1998 12:00AM |
| Credit: | First posted to bugtraq on January 12, 1998 by the author of deliver, Chip Salzenberg <[email protected]>. |
| Vulnerable: |
Slackware Linux 2.3 Slackware Linux 2.2 Slackware Linux 2.1 Debian Linux 1.3.1 |
| Not Vulnerable: | |
Discussion
Multiple Vendor Linux deliver 2.0.12 and below Buffer Overflow Vulnerabilities
deliver is a mail delivery/user processing application native to the Slackware and Debian Linux distributions. The exploitable binary, deliver, is installed setuid root and vulnerable to two buffer overflow attacks. Exploitation of this vulnerability can result in a local, or, under some circumstances, possible remote root compromise.
deliver is a mail delivery/user processing application native to the Slackware and Debian Linux distributions. The exploitable binary, deliver, is installed setuid root and vulnerable to two buffer overflow attacks. Exploitation of this vulnerability can result in a local, or, under some circumstances, possible remote root compromise.
Exploit / POC
Multiple Vendor Linux deliver 2.0.12 and below Buffer Overflow Vulnerabilities
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendor Linux deliver 2.0.12 and below Buffer Overflow Vulnerabilities
Solution:
As an interim solution, one can de-setuid the binary 'deliver'. The author of deliver suggests upgrading to version 2.1.13, the stable release downloadable from the following locations:
rpm: http://www.doc.ic.ac.uk/~jpc1/linux/sunsite/suse/6.0/n1/deliver-2.1.13-29.i386.html
deb: http://www.debian.org/Packages/stable/mail/deliver.html
source: ftp://ftp.debian.org/debian/dists/stable/main/source/mail/deliver_2.1.13.orig.tar.gz
Solution:
As an interim solution, one can de-setuid the binary 'deliver'. The author of deliver suggests upgrading to version 2.1.13, the stable release downloadable from the following locations:
rpm: http://www.doc.ic.ac.uk/~jpc1/linux/sunsite/suse/6.0/n1/deliver-2.1.13-29.i386.html
deb: http://www.debian.org/Packages/stable/mail/deliver.html
source: ftp://ftp.debian.org/debian/dists/stable/main/source/mail/deliver_2.1.13.orig.tar.gz
References
Multiple Vendor Linux deliver 2.0.12 and below Buffer Overflow Vulnerabilities
References:
References: