OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] elm Privilege Escalation

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Tue Jun 24 2003 - 03:48:39 CDT


TITLE:
elm Privilege Escalation

READ ONLINE:
http://www.secunia.com/advisories/9100/

CRITICAL:
Not critical

IMPACT:
Privilege escalation

WHERE:
Local system

SOFTWARE:
elm 2.x (Korean port)

DESCRIPTION:
A vulnerability has been identified in elm Korean port on FreeBSD
allowing malicious local users to gain group "bin" privileges.

The problem is that elm doesn't handle certain environment variables
correct. This allows malicious users to cause a buffer overflow and
possibly execute arbitrary code with group "bin" privileges.

This has been reported for version 2.4h4.1

SOLUTION:
Do not allow untrusted users to access the system or remove elm
Korean port and use a different mail client.

REPORTED BY / CREDITS:
Knud Erik Højgaard

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------