J-Security Center

Title: Sympa Unspecified Buffer Overflow Vulnerability

Severity: HIGH

Description:

Sympa is a mailing list manager written in Perl. It is supported on numerous Unix, and Unix-like platforms including Linux, BSD, Solaris, and others.

Sympa is reported prone to an unspecified buffer overflow vulnerability. This issue presents itself because the application fails to perform boundary checks prior to copying user-supplied data into sensitive process buffers. An attacker may gain unauthorized access to a vulnerable computer in the context of the application by exploiting this issue.

It is reported that this vulnerability exists in a support script of Sympa. Further details were not provided, however, it is conjectured that an attacker supplies excessive data combined with replacement memory addresses and machine code to the script. This may result in overflowing a process buffer leading to memory corruption. If the attacker-supplied code is executed, this issue can allow the attacker to gain unauthorized access or elevated privileges to the vulnerable computer in the context of the application.

Reportedly, the affected script runs with setuid sympa privileges. This BID will be updated when more information becomes available.

Affected Products:

  • Debian Linux 3.0.0
  • Debian Linux 3.0.0 alpha
  • Debian Linux 3.0.0 arm
  • Debian Linux 3.0.0 hppa
  • Debian Linux 3.0.0 ia-32
  • Debian Linux 3.0.0 ia-64
  • Debian Linux 3.0.0 m68k
  • Debian Linux 3.0.0 mips
  • Debian Linux 3.0.0 mipsel
  • Debian Linux 3.0.0 ppc
  • Debian Linux 3.0.0 s/390
  • Debian Linux 3.0.0 sparc
  • Sympa Sympa 3.3.3

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.