|
SCO OpenServer deliver Buffer Overflow Vulnerability
SCO OpenServer 5.0.6 (and possibly earlier versions) ships with several suid bin executables used in printer administration and email-related tasks. One of these utilities is 'deliver', a component which supplies mail delivery services under MMDF. 'deliver' contains a confirmed locally exploitable buffer overflow condition present in the handling of command-line parameters. If properly exploited, this can yield user 'bin' privileges to the attacker. |
|
|
Privacy Statement |