what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

SUN MICROSYSTEMS SECURITY BULLETIN: #00105

SUN MICROSYSTEMS SECURITY BULLETIN: #00105
Posted Jan 19, 1994

Patch advisory for Sun Microsystems. Please read for details.

SHA-256 | 80b57212da5e2adfb4745a40c41f327e8d2c6926484b5298d986c8ffb06cd514

SUN MICROSYSTEMS SECURITY BULLETIN: #00105

Change Mirror Download
SUN MICROSYSTEMS SECURITY BULLETIN: #00105

This information is only to be used for the purpose of alerting
customers to problems. Any other use or re-broadcast of this
information without the express written consent of Sun Microsystems
shall be prohibited.

Sun expressly disclaims all liability for any misuse of this information
by any third party.
============================================================================

All of these patches are available through your local Sun answer centers
worldwide. As well as through anonymous ftp to ftp.uu.net in the
~ftp/sun-dist directory.

Please refer to the Sun BugID and PatchID when requesting patches from Sun
answer centers.

NO README information will be posted in the patch on UUNET. Please refer
the the information below for patch installation instructions.
============================================================================

Sun Bug ID : 1047340
Synopsis : /bin/mail can be caused to invoke a root shell if given the
(im)proper arguments.
Sun Patch ID: 100224-01
Checksum of compressed tarfile 100224-01.tar.Z = 64102 109

============================================================================

Patch-ID# 100224-01
Keywords: mail, delivery, /bin/mail, 4.1, sendmail
Synopsis: SunOS 4.1.1, 4.1, 4.0.3: program "mail" problem in delivering mail + security enhancement
Date: 15 Jan 1990

SunOS release: 4.0.3 4.1 4.1.1

Topic: /bin/mail delivering fix

BugId's fixed with this patch: 1045636 1047340

Architectures for which this patch is available: sun3, sun3x, sun4, sun4c, sun4/490_4.1_PSR_A

Patches which may conflict with this patch: 100161-01. This patch obsoletes
patch 100161-01 since this patch
incorporates 100161-01 fixes plus
the new fixes.
Obsoleted by: SysV Release 4

Problem Description:

Bug ID: 1045636

/bin/mail is the local delivery agent for sendmail. In
some particular instance, /bin/mail parse its argument incorrectly
and therefore, mail are being drop into the bit bucket...

If you have users that has "f" has the second character, you might want
to try the following: (substitute "af" with anyuser with "f" as second
character)

>From any machine except mailhost:

/bin/lib/sendmail -t -v <<END
From: anyuser
to: anyuser
Subject: test
Cc: af <-- substitute any username with second character as "f"
test

END

When the mail arrived on mailhost, sendmail process will invoke
/bin/mail with the following argument "/bin/mail -r anyuser -d af
anyuser". Now you are in trouble. The following are different
scenarios for /bin/mail.

1) /bin/mail -r anyuser -d af <mailmessages worked fine
2) /bin/mail -r anyuser -d anyone af ... <mailmessages worked fine
3) /bin/mail -r anyuser -d af anyone ... <mailmessages !!error!!

in case (3), /bin/mail thinks that you want to read mail instead of
delivering mail. Therefore, mail messages is lost.


BugID: 1047340

/bin/mail can be caused to invoke a root shell if given the
(im)proper arguments.

INSTALL:

AS ROOT:

# mv /bin/mail to /bin/mail.old
# cp $arch/$os/mail to /bin/mail
(where $arch is either sun3 sun4 sun4c or sun3x)
(and where $os is either 4.0.3 4.1 or 4.1.1)
( change the premissions for the newly installed mail)
# chmod 4755 /bin/mail
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close