SCO OpenServer sendmail Buffer Overflow Vulnerability
BID:2593
Info
SCO OpenServer sendmail Buffer Overflow Vulnerability
| Bugtraq ID: | 2593 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 13 2001 12:00AM |
| Updated: | Apr 13 2001 12:00AM |
| Credit: | Reported to bugtraq by Secure Network Operations <[email protected]> on 27 Mar 2001 |
| Vulnerable: |
SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Discussion
SCO OpenServer sendmail Buffer Overflow Vulnerability
SCO OpenServer 5 ships with several suid 'root' executables used for email-related tasks.
This includes sendmail, a component used to deliver or forward email messages to recipients.
'sendmail' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user root privileges to the attacker.
SCO OpenServer 5 ships with several suid 'root' executables used for email-related tasks.
This includes sendmail, a component used to deliver or forward email messages to recipients.
'sendmail' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.
If properly exploited, this can yield user root privileges to the attacker.
References
SCO OpenServer sendmail Buffer Overflow Vulnerability
References:
References: