Bug 11437 - place arbitrary commands in the uucp-queue via smtp
Summary: place arbitrary commands in the uucp-queue via smtp
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: uucp
Version: 6.2
Hardware: i386
OS: Linux
Target Milestone: ---
Assignee: Eido Inoue
QA Contact:
Keywords: Security
Depends On:
TreeView+ depends on / blocked
Reported: 2000-05-16 09:39 UTC by msuencks
Modified: 2008-05-01 15:37 UTC (History)
0 users

Clone Of:
Last Closed: 2001-07-24 04:56:20 UTC

Attachments (Terms of Use)

Description msuencks 2000-05-16 09:39:02 UTC
this is an update to an earlier bug report (#10292)

consider an email with sender's adress like:

<"blabla 0 touch /bin/I_was_here "@somewhere.org>

no consider "somewhere.org" gets its mail via UUCP.

in the uucp queue the "rmail" command will replaced
by the "touch" command the attacker submitted.

Of course this is only an issue if the uucp-system
on the receiving end had "ALL" commands allowed to
be executed via uucp (which is silly at best).

Anyway I think it is not very nice.

as you don't want to touch uucp itself, maybe a
sendmail ruleset will do which denies email with
whitespace in the adress name to be relayed to
uucp queues ..!

Comment 1 Eido Inoue 2002-01-18 21:22:50 UTC
moving this bug to #54466, which addresses the last errata relating to this fix

Note You need to log in before you can comment on or make changes to this bug.