IRIX rmail Vulnerability
BID:460
Info
IRIX rmail Vulnerability
| Bugtraq ID: | 460 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 07 1997 12:00AM |
| Updated: | May 07 1997 12:00AM |
| Credit: | This vulnerability was discovered by Yuri Volobuev <[email protected]> and reported to the Bugtraq mailing list on May 7, 1997. |
| Vulnerable: |
SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 XFS SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 |
| Not Vulnerable: |
SGI IRIX 6.5.1 SGI IRIX 6.5 |
Discussion
IRIX rmail Vulnerability
A vulnerability exists in the rmail utility, included by SGI with it's Irix operating system. By failing to sanity check the contents of an environment variable, arbitrary commands may be executed with gid mail. rmail is used with uucp.
A vulnerability exists in the rmail utility, included by SGI with it's Irix operating system. By failing to sanity check the contents of an environment variable, arbitrary commands may be executed with gid mail. rmail is used with uucp.
Exploit / POC
IRIX rmail Vulnerability
The following example is provided:
setenv LOGNAME blah; command-to-execute
The following example is provided:
setenv LOGNAME blah; command-to-execute
Solution / Fix
IRIX rmail Vulnerability
Solution:
Removal of the setgid bit is highly recommended.
Patches are listed in the attached advisory and are available from SGI at http://support.sgi.com. This issue is addressed in version 6.5 of the operating system and later, users are advised to upgrade to the most recent version.
Solution:
Removal of the setgid bit is highly recommended.
Patches are listed in the attached advisory and are available from SGI at http://support.sgi.com. This issue is addressed in version 6.5 of the operating system and later, users are advised to upgrade to the most recent version.