Sun Microsystems Inc. Information for VU#336083
Uudecode performs inadequate checks on user-specified output files
- Vendor Information Help Date Notified: 15 Jul 2002
- Statement Date:
- Date Updated: 19 Aug 2002
Sun does not believe that this is a security risk as uudecode is functioning as expected and documented. This is an issue if uudecode is blindly executed by a mail reader or other software application. For example if the following /etc/mail/aliases entry is uncommented:
# decode: "|/usr/bin/uudecode"
There aren't any tools in the standard Solaris distribution which require uudecode to be run with privileges.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.