S-214: SurgeMail and WebMail 'Page' Command Vulnerability


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) S-214: SurgeMail and WebMail 'Page' Command Vulnerability
# 1  
Old 02-27-2008
S-214: SurgeMail and WebMail 'Page' Command Vulnerability

SurgeMail and WebMail are prone to a remote fomat-string vulnerability because the applications fail to properly sanitize user-supplied input begore including it in the format-specifier argument of a formatted-printing function. The risk is LOW. A remote attacker may execute arbitrary code with the privileges of the user running the affected applications. Failed exploit attempts will result in a denial of service.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Execute command and show result in web page

Hi everyone, I have two question 1- I want to execute command in shell and after execution result show in a web server. (kind of making UI ) e.g. in shell root ~: show list item1 item2 item(n)in web server in a page draw a table and show those items in itno | name... (1 Reply)
Discussion started by: indeed_1
1 Replies

2. Shell Programming and Scripting

Description of the option print0 in the command find (man page)

This is the description of the option -print0 fon the command find in the man page: What does the "True" in the first line of the description mean? (3 Replies)
Discussion started by: puertas12
3 Replies

3. Shell Programming and Scripting

script for adding page number before page breaks

Hi, If there is an expert that can help: I have many txt files that are produced from pdftotext that include page breaks the page breaks seem to be unix style hex 0C. I want to add page numbers before each page break as in : Page XXXX Regards antman (9 Replies)
Discussion started by: antman
9 Replies

4. Shell Programming and Scripting

Print multiple copies page by page using lp command

Hi I have a pdf file that is being generated using the rwrun command in the shell script. I then have the lp command in the shell script to print the same pdf file. Suppose there are 4 pages in the pdf file , I need to print 2 copies of the first page, 2 copies of the second page , then 2... (7 Replies)
Discussion started by: megha2525
7 Replies

5. Web Development

Page load time- local page

Hi Is there a way to calculate the page load time, I am trying to calculate the load time of a page locally. I found tools to do this over http or https but none that work locally. Any ideas? Thanks. (4 Replies)
Discussion started by: jamie_123
4 Replies

6. UNIX for Dummies Questions & Answers

display command output page per page

Good afternoon, I wonder how i could use unix commands to ease the reading of long command result output ? like the "php -i" or any other command that returns a long answer. I could not find the right terms to Google it or search the forum. Therefore I bother you with this question. ... (3 Replies)
Discussion started by: Mat_k
3 Replies

7. Shell Programming and Scripting

Execute unix command from an html page in windows

i have a problem situation, where i have a html file say click.html. i have a button "ls" in that html page. i run this html file in windows....Now say if i click that "ls" button it must connect to the unix server and execute ls and return the results back to html page in windows. can anyone tell... (8 Replies)
Discussion started by: niteesh_!7
8 Replies

8. Solaris

Creating a Man page for a command

Hi, I would like to develop a man page as the one we usually get when we execute man <command name>. This man page will be for a samll utility that i have written. If this is not possible then what are the available possibilites for creating such help. thanks in advance. (2 Replies)
Discussion started by: raghu.amilineni
2 Replies

9. UNIX for Dummies Questions & Answers

view page command?

Hi All, When I run a command on any shell, many times the output is longer than the screen can hold, so I only can see parts of the output. Is there a command that will show me page by page the results of each command? Thanks, Jared (3 Replies)
Discussion started by: JaredsNew
3 Replies
Login or Register to Ask a Question
rlogin(1c)																rlogin(1c)

Name
       rlogin - remote login

Syntax
       rlogin rhost [-ec] [-8] [-L] [-l username]
       rhost [-ec] [-8] [-L] [-l username]

Description
       The command connects your terminal on the current local host system, lhost, to the remote host system, rhost.

       Each  host  has	a  file  which contains a list of rhosts with which it shares account names.  The host names must be the standard names as
       described in When you use the command to login as the same user on an equivalent host, you do not need to specify a password.

       You can also have a private equivalence list in a file .rhosts in your login directory.	Each line in this file should  contain	the  rhost
       name and a username separated by a space, giving additional cases where logins without passwords are permitted.	If the originating user is
       not equivalent to the remote user, then the remote system prompts for a login and password as in

       To avoid security problems, the .rhosts file must be owned by either the remote user or root and it may not be a symbolic link.

       Your remote terminal type is the same as your local terminal type, which is specified  by  your	environment  TERM  variable.   Except  for
       delays,	all  echoing takes place at the remote site so the rlogin is transparent.  Flow control by and <CTRL/Q>, and flushing of input and
       output on interrupts are handled properly.  The optional argument -8 allows an eight-bit input data path at all times.	Otherwise,  parity
       bits are stripped except when the remote site's stop and start characters are other than and <CTRL/Q>.  A tilde followed by a dot (~.) on a
       separate line disconnects from the remote host, where the tilde (~) is the escape character.  Similarly, a tilde followed  by  <CTRL/Z>	(~
       <CTRL/Z>), where is the suspend character, suspends the rlogin session.

       Substitution  of  the  delayed-suspend  character,  which  is normally <CTRL/Y>, for the suspend character suspends the send portion of the
       rlogin, but allows output from the remote system.  A different escape character may be specified by the -e option.  There is no space sepa-
       rating this option flag and the argument character.

Options
       -8		   Allows an 8-bit input data path at all times.

       -ec		   Uses the specified character as the escape character.  If not specified, uses a tilde (~).

       -l username	   Logs you in as the specified user, not as your user login name.

       -L		   Runs session in litout mode.

Files
       /usr/hosts/*	   for rhost version of the command

See Also
       rsh(1c)

																	rlogin(1c)