Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SCO OpenServer deliver Buffer Overflow Vulnerability

SCO OpenServer 5.0.6 (and possibly earlier versions) ships with several suid bin executables used in printer administration and email-related tasks.

One of these utilities is 'deliver', a component which supplies mail delivery services under MMDF.

'deliver' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters.

If properly exploited, this can yield user 'bin' privileges to the attacker.







 

Privacy Statement
Copyright 2008, SecurityFocus