[5373] in bugtraq

home help back first fref pref prev next nref lref last post

Re: L0pht Advisory: IMAP4rev1 imapd server

daemon@ATHENA.MIT.EDU (Casper Dik)
Thu Oct 9 19:09:07 1997

Date: 	Thu, 9 Oct 1997 10:12:38 +0200
Reply-To: Casper Dik <casper@HOLLAND.SUN.COM>
From: Casper Dik <casper@HOLLAND.SUN.COM>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  Your message of "Wed, 08 Oct 1997 17:45:05 MDT." 
              <Pine.BSF.3.95.971008174307.1952D-100000@alive.znep.com>

>On Wed, 8 Oct 1997, We got Food - Fuel - Ice-cold Beer - and X.509 certificates wrote:
>
>> Scenario:
>>
>>   It is possible to crash the imapd server in several possible places.
>>   Due to the lack of handling for the SIGABRT signal and the nature
>>   of the IMAP protocol in storing folders locally on the server; a core dump
>>   is produced in the users current directory. This core dump contains the
>>   password and shadow password files from the system.
>
>It should be noted that this only works on systems that allow a
>process that has changed UIDs since the last exec to core dump.
>
>Some, such as FreeBSD (and OpenBSD I would guess, and a dozen
>others), don't for exactly this reason.  The same thing came
>up with ftpd a while back.


This was also changed on Solaris 2.6 and may be patched for some
older releases.


Casper

home help back first fref pref prev next nref lref last post