Sympa Buffer Overflow in 'queue.c' Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1013163
|
|
SecurityTracker URL: http://securitytracker.com/id?1013163
|
|
CVE Reference: CAN-2005-0073
(Links to External Site)
|
Date: Feb 11 2005
|
Impact: Execution of arbitrary code via local system, User access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 4.1.3
|
Description: A vulnerability was reported in sympa. A local user may be able to obtain elevated privileges.
A local user can supply a specially crafted 'listname' parameter to trigger a buffer overflow and execute arbitrary code on the target
system. On some systems, sympa is installed with set user id (setuid) 'sympa' user privileges, so the local user can obtain sympa
user privileges.
The flaw resides in 'src/queue.c'.
Erik Sjolund discovered this flaw.
|
Impact: A local user can execute arbitrary code with 'sympa' user privileges.
|
Solution: The vendor has released a fixed version (4.1.3), available at:
http://www.sympa.org/
|
Vendor URL: www.sympa.org/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 11 Feb 2005 08:33:35 -0500
Subject: [none]
|
CVE: CAN-2005-0073
A vulnerability was reported in sympa. A local user may be able to obtain elevated
privileges.
A local user can supply specially crafted input to trigger a buffer overflow and
execute arbitrary code on the target system. On some systems, sympa is installed
with set user id (setuid) 'sympa' user privileges, so the local user can obtain
sympa user privileges.
Erik Sjolund discovered this flaw.
|
|