Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
BID:5122
Info
Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
| Bugtraq ID: | 5122 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2002 12:00AM |
| Updated: | Jun 28 2002 12:00AM |
| Credit: | Vulnerability discovered independently by Joost Pol of PINE Internet and Anton Rang of Sun Microsystems. |
| Vulnerable: |
Sun Solaris 9 Sendmail Consortium Sendmail 8.12.4 Sendmail Consortium Sendmail 8.12.3 Sendmail Consortium Sendmail 8.12.2 Sendmail Consortium Sendmail 8.12.1 Sendmail Consortium Sendmail 8.12 .0 Sendmail Consortium Sendmail 8.11.6 Sendmail Consortium Sendmail 8.11.5 Sendmail Consortium Sendmail 8.11.4 Sendmail Consortium Sendmail 8.11.3 Sendmail Consortium Sendmail 8.11.2 Sendmail Consortium Sendmail 8.11.1 Sendmail Consortium Sendmail 8.11 |
| Not Vulnerable: |
Sendmail Consortium Sendmail 8.12.5 |
Discussion
Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
Sendmail is a freely available, open source mail transport agent. It is available for most Unix and Linux operating systems.
A buffer overflow in the DNS handling code of Sendmail has been discovered. Sendmail attempting to map an address using a TXT query type does not properly check bounds on data returned from the nameserver. Because of this, a malicious nameserver could send a string of arbitrary length to the mail server, resulting in a buffer overflow, and potential code execution. The Sendmail Consortium has stated that the possibility of exploitation is relatively low, as there are no known configurations that use this DNS map option.
Sendmail is a freely available, open source mail transport agent. It is available for most Unix and Linux operating systems.
A buffer overflow in the DNS handling code of Sendmail has been discovered. Sendmail attempting to map an address using a TXT query type does not properly check bounds on data returned from the nameserver. Because of this, a malicious nameserver could send a string of arbitrary length to the mail server, resulting in a buffer overflow, and potential code execution. The Sendmail Consortium has stated that the possibility of exploitation is relatively low, as there are no known configurations that use this DNS map option.
Exploit / POC
Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
Solution:
Apple has addressed this issue in MacOS X 10.2.4/MacOS X Server 10.2.4. Users are advised to upgrade.
Sun has released an alert (Sun Alert ID: 57696) to address this issue in Sun Solaris 9. Please see the alert in Web references for more information.
Fixes are available:
Sun Solaris 9
Sendmail Consortium Sendmail 8.11
Sendmail Consortium Sendmail 8.11.1
Sendmail Consortium Sendmail 8.11.2
Sendmail Consortium Sendmail 8.11.3
Sendmail Consortium Sendmail 8.11.4
Sendmail Consortium Sendmail 8.11.5
Sendmail Consortium Sendmail 8.11.6
Sendmail Consortium Sendmail 8.12 .0
Sendmail Consortium Sendmail 8.12.1
Sendmail Consortium Sendmail 8.12.2
Sendmail Consortium Sendmail 8.12.3
Sendmail Consortium Sendmail 8.12.4
Solution:
Apple has addressed this issue in MacOS X 10.2.4/MacOS X Server 10.2.4. Users are advised to upgrade.
Sun has released an alert (Sun Alert ID: 57696) to address this issue in Sun Solaris 9. Please see the alert in Web references for more information.
Fixes are available:
Sun Solaris 9
Sendmail Consortium Sendmail 8.11
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.11.1
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.11.2
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.11.3
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.11.4
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.11.5
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.11.6
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.12 .0
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.12.1
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.12.2
-
Apple MacOSX10.2.4Combined.dmg
Update for MacOS X 10.2, 10.2.1 and 10.2.2.
http://docs.info.apple.com/article.html?artnum=70168 -
Apple MacOSX10.2.4Update.dmg
Update for MacOS 10.2.3.
http://docs.info.apple.com/article.html?artnum=70167 -
Apple MacOSXServerUpdate10.2.4.dmg
http://docs.info.apple.com/article.html?artnum=70171#English -
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.12.3
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
Sendmail Consortium Sendmail 8.12.4
-
Sendmail Consortium sendmail.8.12.5.tar.gz
ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.5.tar.gz
References
Sendmail DNS Map TXT Record Buffer Overflow Vulnerability
References:
References:
- Security Updates (Apple)
- Sendmail 8.12.5 (Sendmail Consortium)
- Sun Alert ID: 57696 - sendmail(1) (Sun)