+++ to secure your transactions use the Bitcoin Mixer Service +++

 

Bugtraq mailing list archives

Re: SCO 5.0.6 MMDF issues (sendmail 8.9.3)


From: Valdis Kletnieks <Valdis.Kletnieks () VT EDU>
Date: Wed, 28 Mar 2001 10:26:38 -0500

On Tue, 27 Mar 2001 13:39:54 +0100, "Secure Network Operations , Inc." <recon () SNOSOFT COM>  said:

Topic: SCO 5.0.6 MMDF issues (sendmail 8.9.3)

Umm... MMDF has nothing to do with Sendmail 8.9.3, as far as I know.  I've
been alpha/beta testing Sendmails since 8.9.0 and don't remember any MMDF
in there.

version 2.43.3b of MMDF. The sendmail 8.9.3 binary has poor handling of
command line arguments resulting in a buffer overflow.

/opt/K/SCO/MMDF/2.43.3b/usr/lib/sendmail `perl -e 'print "A" x 3000'`

Are you sure that this is not an MMDF binary installed as /usr/lib/sendmail
as a submission agent, to provide compatibility with scripts and programs
that think /usr/lib/sendmail can be used to submit mail?

--
                                Valdis Kletnieks
                                Operating Systems Analyst
                                Virginia Tech

Attachment: _bin
Description:


Current thread: