Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200512-05] Xmail: Privilege escalation through sendmail


Vulnerability Assessment Details

[GLSA-200512-05] Xmail: Privilege escalation through sendmail

Vulnerability Assessment Summary
Xmail: Privilege escalation through sendmail

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200512-05
(Xmail: Privilege escalation through sendmail)


iDEFENSE reported that the AddressFromAtPtr function in the
sendmail program fails to check bounds on arguments passed from other
functions, and as a result an exploitable stack overflow condition
occurs when specifying the "-t" command line option.

Impact

A local attacker can make a malicious call to sendmail,
potentially resulting in code execution with elevated rights.

Workaround

There is no known workaround at this time.

References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2943
http://www.idefense.com/application/poi/display?id=321&type=vulnerabilities&flashstatus=true


Solution:
All Xmail users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=mail-mta/xmail-1.22"


Network Security Threat Level: High


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2005 Michel Arboi

Cables, Connectors


Cisco Systems NCS2K-20-SMRFS-L optical multiplexor CISCO EXCESS picture

Cisco Systems NCS2K-20-SMRFS-L optical multiplexor CISCO EXCESS

$3599.00



Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24 picture

Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24

$117.00



Cisco NC55-MPA-12T-S Port Adapter NCS 5500 Modular Chassis CISCO EXCESS UNIT picture

Cisco NC55-MPA-12T-S Port Adapter NCS 5500 Modular Chassis CISCO EXCESS UNIT

$3900.00



Cisco 1100 Terminal - gateway - rack-mountable C1100TGX-1N24P32A picture

Cisco 1100 Terminal - gateway - rack-mountable C1100TGX-1N24P32A

$1349.00



Cisco WS-C3850-48P-L 48-Port Gigabit 3850 PoE Switch w/ 715W+ C3850-NM-4-1G Mod picture

Cisco WS-C3850-48P-L 48-Port Gigabit 3850 PoE Switch w/ 715W+ C3850-NM-4-1G Mod

$83.00



Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850 picture

Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850

$38.99



 Lot of 4 Cisco QSFP-40G-SR-BD 10-2945-02 Transceiver Modules  Hologram picture

Lot of 4 Cisco QSFP-40G-SR-BD 10-2945-02 Transceiver Modules Hologram

$47.99



Cisco Catalyst WS-C2960-48TT-L V02 48 Port Fast Ethernet Switch picture

Cisco Catalyst WS-C2960-48TT-L V02 48 Port Fast Ethernet Switch

$34.00



Cisco C9200 48-Port Gigabit Network Switch With Ears P/N: C9200-48T-E Dual Power picture

Cisco C9200 48-Port Gigabit Network Switch With Ears P/N: C9200-48T-E Dual Power

$799.97



New Cisco C9200-NM-4X Catalyst 9200 Series Network Module 4 X 10GE *MINT* picture

New Cisco C9200-NM-4X Catalyst 9200 Series Network Module 4 X 10GE *MINT*

$429.97



Discussions

No Discussions have been posted on this vulnerability.