|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Sun Microsystems Inc. Information for VU#336083
| Date Notified | 07/15/2002 |
| Date Modified | 12/13/2002 11:42:03 AM |
| Status Summary | Vulnerable |
Vendor StatementSun does not believe that this is a security risk as uudecode is functioning as expected and documented. This is an issue if uudecode is blindly executed by a mail reader or other software application. For example if the following /etc/mail/aliases entry is uncommented:
# decode: "|/usr/bin/uudecode"
There aren't any tools in the standard Solaris distribution which require uudecode to be run with privileges.US-CERT AddendumThe CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |