Vulnerability Development mailing list archives
Re: /usr/bin/Mail buffer 0verfl0w
From: BAILLEUX Christophe <cb () T-ONLINE FR>
Date: Fri, 2 Mar 2001 12:48:21 +0100
Slackware 7.1 : tshaw:~$ ls -l /usr/bin/Mail -rwxr-xr-x 1 root bin 75996 Jun 9 2000 /usr/bin/Mail* tshaw:~$ tshaw:~$ Mail Mail version 8.1 6/6/93. Type ? for help. & t 0x2240 0: Invalid message number & t 0 x 2240 0: Invalid message number & On Thu, 1 Mar 2001, K2 wrote:
SosPiro wrote:I found a buffer oveflow in /usr/bin/Mail,it's suid by default on my Slakware 7.00 K2.2.13 This is the problem: SunsetZer0:#Mail Mail version 8.1 6/6/93. Type ? for help "/var/spool/mail/root": 2 messages 2 unreadU 1 root Thu Sep 15 02:23 33/1257"hole in /usr/bin/Mail" U 2 sospiro Sat Oct 9 18:19 126/6192 "Owned!Owned!" & t 0 x 2240 0:Invalid message number "Source" stack over-pop Segmentation Fault sospiro "ALl We WaNt is T0 bE HapPy" ---------------------------------You sure that isnt sGid? snow:~# ls -l /usr/bin/Mail -rwx--s--x 1 root mail 75968 Aug 19 1999 /usr/bin/Mail* That's on my slackware box. -- K2
Current thread:
- Re: /usr/bin/Mail buffer 0verfl0w, (continued)
- Re: /usr/bin/Mail buffer 0verfl0w syzop (Mar 01)
- Re: /usr/bin/Mail buffer 0verfl0w Knud Erik Hojgaard - CyberCity Support (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Knud Erik Hojgaard - CyberCity Support (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Jan Kluka (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Lord_Ph@ntom (Mar 06)
- Re: /usr/bin/Mail buffer 0verfl0w Syzop (Mar 06)
- Re: /usr/bin/Mail buffer 0verfl0w Maciek Pasternacki (Mar 07)
- Re: /usr/bin/Mail buffer 0verfl0w syzop (Mar 01)
- Re: /usr/bin/Mail buffer 0verfl0w BAILLEUX Christophe (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Joe (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Blue Boar (Mar 03)
- Crediting/Communication (Was: Re: [VULN-DEV] /usr/bin/Mail buffer 0verfl0w) Syzop (Mar 03)