OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Kris Kennaway (krisOBSECURITY.ORG)
Date: Fri Feb 23 2001 - 15:34:36 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Thu, Feb 22, 2001 at 02:09:35PM -0800, securityTURBOLINUX.COM wrote:
    > Sendmail, launched with the -bt command-line switch, enters its special
    > "address test" mode. Under these conditions, it is vulnerable to a
    > segmentation fault which can occur when trying to set a class in ad-
    > dress test mode due to a negative array index.
    >
    > 2. Impact
    >
    > A user can gain root privileges.

    This was proven to be wrong - this bug is not believed to have any
    security impact.

    Kris

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.4 (FreeBSD)
    Comment: For info see http://www.gnupg.org

    iD8DBQE6ltdsWry0BWjoQKURAmbqAKD1S+X0trV8KJ/8U5lQ4mxLqY7IhQCg6qmU
    CEgm282wkDpjkkcAsG8Nzzg=
    =6Sum
    -----END PGP SIGNATURE-----