SCO MMDF Buffer Overflow Vulnerability
BID:997
Info
SCO MMDF Buffer Overflow Vulnerability
| Bugtraq ID: | 997 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-0158 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | This vulnerability was made public in a Network Associates Security Advisory, dated February 15, 2000. |
| Vulnerable: |
SCO Open Server 5.0.6 SCO Open Server 5.0.5 SCO Open Server 5.0.4 SCO Open Server 5.0.3 SCO Open Server 5.0.2 SCO Open Server 5.0.1 SCO Open Server 5.0 |
| Not Vulnerable: | |
Discussion
SCO MMDF Buffer Overflow Vulnerability
A number of buffer overflow vulnerabilities exist in the MMDF mail daemon, as shipped by SCO with their OpenServer Operating System. By sending long, well crafted buffers to the smtpd mail daemon, as part of a "MAIL FROM:" command, it may be possible for an attacker to gain access to the machine under the user running the smtpd program. It is, by default, run as user mmdf.
This vulnerability is specific to the version of MMDF shipped from SCO. A number of people have indicated that these problems have not existed in public versions of MMDF for a number of years.
A number of buffer overflow vulnerabilities exist in the MMDF mail daemon, as shipped by SCO with their OpenServer Operating System. By sending long, well crafted buffers to the smtpd mail daemon, as part of a "MAIL FROM:" command, it may be possible for an attacker to gain access to the machine under the user running the smtpd program. It is, by default, run as user mmdf.
This vulnerability is specific to the version of MMDF shipped from SCO. A number of people have indicated that these problems have not existed in public versions of MMDF for a number of years.
Exploit / POC
SCO MMDF Buffer Overflow Vulnerability
x
x
Solution / Fix
SCO MMDF Buffer Overflow Vulnerability
Solution:
SCO has made patches available for this issue. They can be downloaded from http://www.sco.com/security.
SCO Open Server 5.0
SCO Open Server 5.0.1
SCO Open Server 5.0.2
SCO Open Server 5.0.3
SCO Open Server 5.0.4
SCO Open Server 5.0.5
SCO Open Server 5.0.6
Solution:
SCO has made patches available for this issue. They can be downloaded from http://www.sco.com/security.
SCO Open Server 5.0
-
SCO sse062.tar.Z
ftp://ftp.sco.com/SSE/sse062.tar.Z
SCO Open Server 5.0.1
-
SCO sse062.tar.Z
ftp://ftp.sco.com/SSE/sse062.tar.Z
SCO Open Server 5.0.2
-
SCO sse062.tar.Z
ftp://ftp.sco.com/SSE/sse062.tar.Z
SCO Open Server 5.0.3
-
SCO sse062.tar.Z
ftp://ftp.sco.com/SSE/sse062.tar.Z
SCO Open Server 5.0.4
-
SCO sse062.tar.Z
ftp://ftp.sco.com/SSE/sse062.tar.Z
SCO Open Server 5.0.5
-
SCO sse062.tar.Z
ftp://ftp.sco.com/SSE/sse062.tar.Z
SCO Open Server 5.0.6
-
SCO sse062.tar.Z
ftp://ftp.sco.com/SSE/sse062.tar.Z