Vulnerability Development mailing list archives
Re: /usr/bin/Mail buffer 0verfl0w
From: Enrique Maglietta <emagliet () UNCOMA EDU AR>
Date: Thu, 1 Mar 2001 13:12:01 -0300
El miƩ, 28 feb 2001, escribiste:
I found a buffer oveflow in /usr/bin/Mail,it's suid by default on my Slakware 7.00 K2.2.13 This is the problem: SunsetZer0:#Mail Mail version 8.1 6/6/93. Type ? for help "/var/spool/mail/root": 2 messages 2 unreadU 1 root Thu Sep 15 02:23 33/1257"hole in /usr/bin/Mail" U 2 sospiro Sat Oct 9 18:19 126/6192 "Owned!Owned!" & t 0 x 2240 0:Invalid message number "Source" stack over-pop Segmentation Fault
I'm test on a SuSE 7.0 , and there is no problem & t 0x2240 0: Invalid message number & t 0 x 2240 0: Invalid message number &
Current thread:
- /usr/bin/Mail buffer 0verfl0w SosPiro (Mar 01)
- Re: /usr/bin/Mail buffer 0verfl0w Enrique Maglietta (Mar 01)
- Re: /usr/bin/Mail buffer 0verfl0w syzop (Mar 01)
- Re: /usr/bin/Mail buffer 0verfl0w Knud Erik Hojgaard - CyberCity Support (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Knud Erik Hojgaard - CyberCity Support (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Jan Kluka (Mar 02)
- Re: /usr/bin/Mail buffer 0verfl0w Lord_Ph@ntom (Mar 06)
- Re: /usr/bin/Mail buffer 0verfl0w Syzop (Mar 06)
- Re: /usr/bin/Mail buffer 0verfl0w Maciek Pasternacki (Mar 07)
- Re: /usr/bin/Mail buffer 0verfl0w syzop (Mar 01)
- Re: /usr/bin/Mail buffer 0verfl0w Enrique Maglietta (Mar 01)