Bug 11437 - place arbitrary commands in the uucp-queue via smtp
place arbitrary commands in the uucp-queue via smtp
Status: CLOSED DEFERRED
Product: Red Hat Linux
Classification: Retired
Component: uucp (Show other bugs)
6.2
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Eido Inoue
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2000-05-16 05:39 EDT by msuencks
Modified: 2008-05-01 11:37 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2001-07-24 00:56:20 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description msuencks 2000-05-16 05:39:02 EDT
this is an update to an earlier bug report (#10292)

consider an email with sender's adress like:


<"blabla 0 touch /bin/I_was_here "@somewhere.org>



no consider "somewhere.org" gets its mail via UUCP.

in the uucp queue the "rmail" command will replaced
by the "touch" command the attacker submitted.

Of course this is only an issue if the uucp-system
on the receiving end had "ALL" commands allowed to
be executed via uucp (which is silly at best).

Anyway I think it is not very nice.

as you don't want to touch uucp itself, maybe a
sendmail ruleset will do which denies email with
whitespace in the adress name to be relayed to
uucp queues ..!
Comment 1 Eido Inoue 2002-01-18 16:22:50 EST
moving this bug to #54466, which addresses the last errata relating to this fix

Note You need to log in before you can comment on or make changes to this bug.