SGI MediaMail Memory Corruption Vulnerability
BID:4959
Info
SGI MediaMail Memory Corruption Vulnerability
| Bugtraq ID: | 4959 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 07 2002 12:00AM |
| Updated: | Jun 07 2002 12:00AM |
| Credit: | Vulnerability announced by SGI Security Coordinator. |
| Vulnerable: |
SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 |
| Not Vulnerable: | |
Discussion
SGI MediaMail Memory Corruption Vulnerability
MediaMail is a mail application distributed with SGI IRIX.
It has been reported by SGI that certain command line argument passed to MediaMail may result in core dumps. These core dumps are due to memory corruption, and are likely exploitable. The MediaMail and MediaMail Pro applications are typically installed setgid mail. If attackers successfuly exploit MediaMail, they may gain these privileges.
MediaMail is a mail application distributed with SGI IRIX.
It has been reported by SGI that certain command line argument passed to MediaMail may result in core dumps. These core dumps are due to memory corruption, and are likely exploitable. The MediaMail and MediaMail Pro applications are typically installed setgid mail. If attackers successfuly exploit MediaMail, they may gain these privileges.
Exploit / POC
SGI MediaMail Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SGI MediaMail Memory Corruption Vulnerability
Solution:
SGI has stated that no patches will be produced to fix this vulnerability. Additionally, SGI has recommended removing any vulnerable installations of the software.
Solution:
SGI has stated that no patches will be produced to fix this vulnerability. Additionally, SGI has recommended removing any vulnerable installations of the software.
References
SGI MediaMail Memory Corruption Vulnerability
References:
References: