OpenWindows mailtool(1) Client for Sun Solaris Can Be Crashed By Remote Users
|
|
SecurityTracker Alert ID: 1005723 |
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Nov 28 2002
|
Impact: Denial of service via local system, Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): OpenWindows 3.6, 3.6.1 and 3.6.2
|
Description: A vulnerability was reported in the OpenWindows mailtool(1) for Sun Solaris. A remote user can cause a target user's mailtool client to crash.
Sun issued a Sun Alert (48216) warning of potential denial of service issues with
OpenWindow's Mailtool. A local or remote user can create a specially crafted mail message that will cause a segmentation fault in mailtool(1).
|
Impact: A remote user can cause a target user's mailtool client to crash.
|
Solution: Sun has issued the following patches:
SPARC
* Solaris 2.6: patch 106650-05 or later
* Solaris 7: patch 106725-03 or
later
* Solaris 8: patch 113792-01 or later
Intel
* Solaris 2.6: patch 106659-05 or later
* Solaris 7: patch
106737-04 or later
* Solaris 8 with patch 113793-01 or later
Sun indicates that customers running Solaris 2.5.1 should upgrade
to Solaris 2.6 (or later) with the appropriate patches.
|
Vendor URL: sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F48216 (Links to External Site)
|
Cause: Exception handling error
|
Underlying OS: UNIX (Solaris - SunOS)
|
Underlying OS Comments: 2.5.1, 2.6, 7, 8
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 28 Nov 2002 02:51:43 -0500
Subject: Possible Denial of Service for OpenWindow's Mailtool Users
|
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F48216
Sun issued a Sun Alert (48216) warning of potential denial of service issues with
OpenWindow's Mailtool. A local or remote user can create a specially crafted mail message
that will cause a segmentation fault in mailtool(1).
The following operating system versions are affected: Solaris 2.5.1, 2.6, 7, 8
Sun reports that this issue is with OpenWindows 3.6, 3.6.1 and 3.6.2.
According to the report, Solaris 9 is not affected because the OpenWindows' mailtool(1) is
not supported on Solaris 9.
Sun has issued the following patches:
SPARC
* Solaris 2.6 with patch 106650-05 or later
* Solaris 7 with patch 106725-03 or later
* Solaris 8 with patch 113792-01 or later
Intel
* Solaris 2.6 with patch 106659-05 or later
* Solaris 7 with patch 106737-04 or later
* Solaris 8 with patch 113793-01 or later
Sun indicates that customers running Solaris 2.5.1 should upgrade to Solaris 2.6 (or
later) with the appropriate patches.
-----
* Sun Alert ID: 48216
* Synopsis: Possible Denial of Service for OpenWindows mailtool(1) Users
* Category: Security
* Product: Solaris, OpenWindows
* BugIDs: 4755258
* Avoidance: Workaround, Patch
* State: Resolved
* Date Released: 27-Nov-2002
* Date Closed: 27-Nov-2002
* Date Modified:
|
|