Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA248] DSA-248-1 hypermail


Vulnerability Assessment Details

[DSA248] DSA-248-1 hypermail

Vulnerability Assessment Summary
DSA-248-1 hypermail

Detailed Explanation for this Vulnerability Assessment

Ulf Härnhammar discovered two problems in hypermail, a program to
create HTML archives of mailing lists.
A possible hacker could craft a long filename for an attachment that would
overflow two buffers when a certain option for interactive use was
given, opening the possibility to inject arbitrary code. This code
would then be executed under the user id hypermail runs as, mostly as
a local user. Automatic and silent use of hypermail does not seem to
be affected.
The CGI program mail, which is not installed by the Debian package,
does a reverse look-up of the user's IP number and copies the
resulting hostname into a fixed-size buffer. A specially crafted DNS
reply could overflow this buffer, opening the program to an exploit.
For the stable distribution (woody) this problem has been fixed in
version 2.1.3-2.0.
For the old stable distribution (potato) this problem has been fixed
in version 2.0b25-1.1.
For the unstable distribution (sid) this problem has been fixed
in version 2.1.6-1.
We recommend that you upgrade your hypermail packages.


Solution : http://www.debian.org/security/2003/dsa-248
Network Security Threat Level: High

Networks Security ID: 6689, 6690

Vulnerability Assessment Copyright: This script is (C) 2005 Michel Arboi

Cables, Connectors

Dell 300GB 3.5'' SAS 6G 15K Server Hard Drive 0F617N F617N R710 R510 R720 R520
$59.95
Dell 300GB 3.5'' SAS 6G 15K Server Hard Drive 0F617N F617N R710 R510 R720 R520 pictureDell R515 Wrty thru 7-23-17 1*AMD 4170HE, 2*1TB SATA, PERC H700, 4GB, PowerEdge
$1279.0
Dell R515 Wrty thru 7-23-17 1*AMD 4170HE, 2*1TB SATA, PERC H700, 4GB, PowerEdge  pictureDell R910 Warranty through 3-18-2018. 4*X7560, 4*300GB 10K SAS, H700, 128GB Ram
$6189.0
Dell R910 Warranty through 3-18-2018. 4*X7560, 4*300GB 10K SAS, H700, 128GB Ram pictureDell 1TB 3.5'' LFF SATA 3G 7.2K Server Hard Drive 08CGTN 8CGTN R720 R520
$74.94
Dell 1TB 3.5'' LFF SATA 3G 7.2K Server Hard Drive 08CGTN 8CGTN R720 R520 picture


Discussions

No Discussions have been posted on this vulnerability.