Solaris /usr/bin/mail -m Local Buffer Overflow Vulnerability
BID:672
Info
Solaris /usr/bin/mail -m Local Buffer Overflow Vulnerability
| Bugtraq ID: | 672 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 12 1999 12:00AM |
| Updated: | Sep 12 1999 12:00AM |
| Credit: | This vulnerability was discovered by Brock Tellier <[email protected]>. |
| Vulnerable: |
Sun Solaris 7.0_x86 Sun Solaris 7.0 |
| Not Vulnerable: | |
Discussion
Solaris /usr/bin/mail -m Local Buffer Overflow Vulnerability
A buffer overflow vulnerability in the '/usr/bin/mail' program's handling of the '-m' command line argument allows local users to obtain access to the 'mail' group.
A buffer overflow vulnerability in the '/usr/bin/mail' program's handling of the '-m' command line argument allows local users to obtain access to the 'mail' group.
Solution / Fix
Solaris /usr/bin/mail -m Local Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
In the mean time turn off the setgid bit from the '/usr/bin/mail' executable.
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
In the mean time turn off the setgid bit from the '/usr/bin/mail' executable.