Re: [Corrected message] This OpenBSD local root hole may affect some FreeBSD systems

From: Nicolas Rachinsky (list@rachinsky.de)
Date: 04/11/02


Date: Thu, 11 Apr 2002 22:45:17 +0200
From: Nicolas Rachinsky <list@rachinsky.de>
To: security@FreeBSD.ORG


* Brett Glass <brett@lariat.org> [2002-04-11 14:12:01 -0600]:
> [This is a corrected version of the previous message, which omitted
> the word "isn't" near the beginning of the second paragraph.]
>
> The vulnerability described in the message below is a classic
> "in-band signalling" problem that may give an unauthorized user
> the ability to run an arbitrary command as root.
>
> Fortunately, the vulnerability isn't present in FreeBSD's daily, weekly,
> and monthly maintenance scripts, because they use sendmail rather
> than /bin/mail. Nonetheless, the same patch should be applied to
> FreeBSD's /bin/mail due to the possibility that other privileged
> utilities (or user-written scripts) might use /bin/mail instead of
> sendmail to create e-mail messages.

man mail says:
     -I Forces mail to run in interactive mode even when input is not a
           terminal. In particular, the `~' special character when sending
           mail is only active in interactive mode.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail
    ... There is a vulnerability in sendmail that may allow remote attackers ... vulnerable sendmail servers on the interior of a network ... Many vendors include vulnerable sendmail servers as part of their ...
    (Cert)
  • CERT Advisory CA-2003-12 Buffer Overflow in Sendmail
    ... execute arbitrary code with the privileges of the sendmail daemon, ... There is a remotely exploitable vulnerability in sendmail that could ... Apply a patch from your vendor ... the CERT/CC ...
    (Cert)
  • Technical Support Bulletin
    ... Sendmail is a MTA that resources. ... headers are parsed ... This vulnerability may allow ... attacker to cause a denial of service attack ...
    (AIX-L)
  • sendmail vuln advisories (CVE-2006-0058)
    ... Sendmail, Inc. has recently become aware of a security vulnerability in certain versions of sendmail Mail Transfer Agent and UNIX and Linux products that contain it. ... Sendmail was notified by security researchers at ISS that, under some specific timing conditions, this vulnerability may permit a specifically crafted attack to take over the sendmail MTA process, allowing remote attackers to execute commands and run arbitrary programs on the system running the MTA, affecting email delivery, or tampering with other programs and data on this system. ...
    (Bugtraq)
  • [Full-Disclosure] Fwd: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail
    ... CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail ... There is a vulnerability in sendmail that may allow remote attackers ...
    (Full-Disclosure)

Quantcast