Bug 5002 - Mars-Nwe security vulnerability
Mars-Nwe security vulnerability
Product: Red Hat Linux
Classification: Retired
Component: mars-nwe (Show other bugs)
All Linux
high Severity medium
: ---
: ---
Assigned To: David Lawrence
: Security
Depends On:
  Show dependency treegraph
Reported: 1999-09-08 19:32 EDT by zurk
Modified: 2008-05-01 11:37 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 1999-09-14 13:40:29 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description zurk 1999-09-08 19:32:37 EDT
I'm not too sure that redhat 6 is vulnerable to this but you
might want to check it out. mars-new package is/has a
boundary condition error..a local exploitable buffer
overflow. Its a root exploit. All versions upto and
including 0.99 (redhat 6?) are believed to be vulnerable to
this. Also wanted to report that anaconda (redhat 6.1's
installer) seems to crash and reboot the machine when it
cant detect the video card (i.e. it cant load the VGA_16
server). not sure where to put that one. Also you might want
to check or change the 6.1 mars-nwe too.
Comment 1 Bill Nottingham 1999-09-09 10:25:59 EDT
Actually, the code that calls system (with the buffer
overflow) is never used.
Comment 2 Bill Nottingham 1999-09-14 13:40:59 EDT
Fixed in the errata release.

Note You need to log in before you can comment on or make changes to this bug.