Gauntlet Firewall for Unix and WebShield CSMAP and smap/smapd Buffer Overflow Vulnerability
BID:3290
Info
Gauntlet Firewall for Unix and WebShield CSMAP and smap/smapd Buffer Overflow Vulnerability
| Bugtraq ID: | 3290 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1456 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2001 12:00AM |
| Updated: | Mar 19 2015 09:07AM |
| Credit: | Discovered by Jim Stickley of Garrison Technologies and published in a PGP Security Advisory on September 4, 2001. |
| Vulnerable: |
SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 Securecomputing PGP e-ppliance 300 2.0 Securecomputing PGP e-ppliance 300 1.5 Securecomputing PGP e-ppliance 300 1.0 Network Associates PGP e-ppliance 300 series 2.0 Network Associates PGP e-ppliance 300 series 1.5 Network Associates PGP e-ppliance 300 series 1.0 Network Associates Gauntlet Firewall for Unix 6.0 Network Associates Gauntlet Firewall for Unix 5.5 Network Associates Gauntlet Firewall for Unix 5.0 Network Associates Gauntlet Firewall 4.2 McAfee WebShield for Solaris 4.0 |
| Not Vulnerable: | |
Discussion
Gauntlet Firewall for Unix and WebShield CSMAP and smap/smapd Buffer Overflow Vulnerability
A boundary condition error exists in the smap/smapd and CSMAPD daemons, shipped with several popular Network Associates products. The smap/smapd and CSMAP daemons are proxy servers used to handle e-mail transactions for both inbound and outbound e-mail.
By successfully exploiting this condition, an attacker may be able to cause arbitrary code/commands to be executed on a vulnerable system with the privileges of the attacked daemon.
Additional technical details are currently unknown.
Some versions of SGI IRIX shipped with the Gauntlet Firewall package, and in the past it was a supported SGI product. While it is no longer being supported, SGI IRIX versions 6.5.2, 6.5.3, 6.5.4 and 6.5.5 may be prone to this issue.
A boundary condition error exists in the smap/smapd and CSMAPD daemons, shipped with several popular Network Associates products. The smap/smapd and CSMAP daemons are proxy servers used to handle e-mail transactions for both inbound and outbound e-mail.
By successfully exploiting this condition, an attacker may be able to cause arbitrary code/commands to be executed on a vulnerable system with the privileges of the attacked daemon.
Additional technical details are currently unknown.
Some versions of SGI IRIX shipped with the Gauntlet Firewall package, and in the past it was a supported SGI product. While it is no longer being supported, SGI IRIX versions 6.5.2, 6.5.3, 6.5.4 and 6.5.5 may be prone to this issue.
Solution / Fix
Gauntlet Firewall for Unix and WebShield CSMAP and smap/smapd Buffer Overflow Vulnerability
Solution:
A patch to repair this vulnerability is available for all Network Associates products listed as being vulnerable at ftp://ftp.nai.com/pub/security/ and http://www.pgp.com/naicommon/download/upgrade/upgrades-patch.asp for the Gauntlet and PGP e-ppliance products and www.mcafeeb2b.com for the McAfee e-ppliance and WebShield products.
Solution:
A patch to repair this vulnerability is available for all Network Associates products listed as being vulnerable at ftp://ftp.nai.com/pub/security/ and http://www.pgp.com/naicommon/download/upgrade/upgrades-patch.asp for the Gauntlet and PGP e-ppliance products and www.mcafeeb2b.com for the McAfee e-ppliance and WebShield products.
References
Gauntlet Firewall for Unix and WebShield CSMAP and smap/smapd Buffer Overflow Vulnerability
References:
References:
- PGP Security - CSMAP and smap/smapd BUFFER OVERFLOW VULNERABILITY ADVISORY (Network Associates Inc.)