exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Deliver Race Condition

Deliver Race Condition
Posted Mar 25, 2010
Authored by Dan Rosenberg

The Deliver mail delivery program suffers from several race condition vulnerabilities.

tags | advisory, vulnerability
advisories | CVE-2010-0439
SHA-256 | 05333665d18be17f37a1fdfcd655bd89040d70e095e671c464fef3c39c9bf329

Deliver Race Condition

Change Mirror Download
==================================
 Deliver, multiple vulnerabilites
 March 24, 2010
 CVE-2010-0439
==================================

==Description==

Deliver (http://deliver.sourceforge.net/), a mail delivery program
installed suid
root as /usr/bin/deliver, is vulnerable to several race conditions that can be
exploited by a local attacker using symbolic links.  On systems using Deliver
over NFS, these attacks can result in gaining root privileges via
taking ownership
of critical system files.  On other systems, these attacks can result in
denial-of-service conditions and information disclosure.  In addition, users can
deny service to other users by creating lockfiles for other users' mailboxes.

==Solution==

Users are advised to discontinue use of Deliver in the absence of a patch or
new release from the developer.

==Credits==

These vulnerabilities were discovered by Dan Rosenberg
(dan.j.rosenberg@gmail.com).

==Timeline==

1/14/10 - Vulnerabilities discovered
1/27/10 - Developer notified
1/27/10 - Developer response, fix planned
3/20/10 - Fix deadlines repeatedly passed, disclosure date set at 3/24/10
3/24/10 - Disclosure

==References==

CVE identifier CVE-2010-0439 has been assigned to these issues.
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close