Re: Solaris 2.4 pop buffer overrun

From: Alan Thew (Alan.Thewat_private)
Date: Mon Aug 10 1998 - 09:16:49 PDT

  • Next message: Patrick Oonk: "Source Back Orifice Unix client released"

    This looks like SIMS 1.0/2.0 which has imap4/pop3 and was available for
    solaris 2.5.1 and lower....
    
    --
    Alan Thew                                       alan.thewat_private
    Computing Services,University of Liverpool      Fax: +44 151 794-4442
    
    On Mon, 10 Aug 1998, Julio Casal wrote:
    
    >>uhhh...  since when does sun have its own pop3 daemon??
    >>
    >
    >It may not be shipped with Solaris 2.4, sorry about that, but SUNWpop exists,
    >I think it came as an extra with first Netra servers. I've seen it in some
    >installations by Sun.
    >
    >Julio.
    >
    >
    >>On 05-Aug-98 Julio Casal wrote:
    >>> An old one I guess known but I never saw it in the list:
    >>>
    >>> Solaris 2.4 popper has an overflow in the username explotaible obviously
    >>> as root.
    >>> It's also easy to get root's shadow entry in the core dumped just
    >failing to
    >>> log as root before overruning the username.
    >>>
    >>> Cheers,
    >>> Julio.
    >>
    >>
    >>
    >>-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
    >>Daniel Leeds                          Systems Administrator
    >>dleedsat_private                          DigitalFacades
    >>-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
    >>
    >
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:11:55 PDT