Ecartis/Listar Buffer Overflow Vulnerability

Ecartis is the new name for the Listar software product. Listar is a mailing list management package for Linux, BSD, and other Unix like operating systems.

A vulnerability has been announced in some versions of Ecartis and Listar. It is possible for user supplied input to overflow a buffer. This may result in stack data being overwritten with user supplied values, including the return address of a function call. If successfully exploited, this may result in the execution of arbitrary code.

Listar normally runs as the non-privileged user 'listar'. However, exploitation of this vulnerability may result in local access for an attacker. From a local standpoint, further elevation of privileges may be easier to obtain.


