Title: SGI MediaMail Memory Corruption Vulnerability
Severity: MODERATE
Description:
MediaMail is a mail application distributed with SGI IRIX.
Problems with MediaMail have been reported that could lead to a local user gaining elevated privileges.
It has been reported by SGI that certain command line argument passed to MediaMail may result in core dumps. These core dumps are due to memory corruption, and are likely exploitable. The MediaMail and MediaMail Pro applications are typically installed setgid mail. If attackers successfuly exploit MediaMail, they may gain these privileges.
This issue is likely either a buffer overflow or format string vulnerability. As there are no details available, the method of exploitation of these vulnerabilities is uncertain. In the case of a buffer overflow vulnerability, it is likely that an attacker will be able to execute code by passing an exceptionally long string and attacker-supplied instructions to one or several of the arguments handled by MediaMail. In the case of a format string vulnerability, an attacker will likely pass a malicious format string and attacker-supplied instructions with one or several of the arguments handled by MediaMail.
It should be noted that MediaMail Pro is also affected by this vulnerability. An attacker gaining an effective gid of mail will be able to read other users mail.
Affected Products:
- SGI IRIX 5.0.0
- SGI IRIX 5.0.1
- SGI IRIX 5.1.0
- SGI IRIX 5.1.1
- SGI IRIX 5.2.0
- SGI IRIX 5.3.0
- SGI IRIX 6.0.0
- SGI IRIX 6.0.1
- SGI IRIX 6.1.0
- SGI IRIX 6.2.0
- SGI IRIX 6.3.0
- SGI IRIX 6.4.0
- SGI IRIX 6.5.0
- SGI IRIX 6.5.1
- SGI IRIX 6.5.10
- SGI IRIX 6.5.11
- SGI IRIX 6.5.12
- SGI IRIX 6.5.13
- SGI IRIX 6.5.14
- SGI IRIX 6.5.15
- SGI IRIX 6.5.16
- SGI IRIX 6.5.2
- SGI IRIX 6.5.3
- SGI IRIX 6.5.4
- SGI IRIX 6.5.5
- SGI IRIX 6.5.6
- SGI IRIX 6.5.7
- SGI IRIX 6.5.8
- SGI IRIX 6.5.9
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.