SCO OpenServer deliver Buffer Overflow Vulnerability
BID:2583
Info
SCO OpenServer deliver Buffer Overflow Vulnerability
| Bugtraq ID: | 2583 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0587 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 13 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Reported to bugtraq by Secure Network Operations <[email protected]> on 27 Mar 2001 |
| Vulnerable: |
SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Discussion
SCO OpenServer deliver Buffer Overflow Vulnerability
SCO OpenServer 5.0.6 (and possibly earlier versions) ships with several suid bin executables used in printer administration and email-related tasks.
One of these utilities is 'deliver', a component which supplies mail delivery services under MMDF.
'deliver' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user 'bin' privileges to the attacker.
SCO OpenServer 5.0.6 (and possibly earlier versions) ships with several suid bin executables used in printer administration and email-related tasks.
One of these utilities is 'deliver', a component which supplies mail delivery services under MMDF.
'deliver' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user 'bin' privileges to the attacker.
References
SCO OpenServer deliver Buffer Overflow Vulnerability
References:
References: