ripMIME MIME Attachment Decoding Weakness
BID:10848
Info
ripMIME MIME Attachment Decoding Weakness
| Bugtraq ID: | 10848 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2004 12:00AM |
| Updated: | Aug 03 2004 12:00AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
plDaniels ripMime 1.3.2 .2 plDaniels ripMime 1.3.2 .0 plDaniels ripMime 1.2.7 plDaniels ripMime 1.2.6 plDaniels ripMime 1.2.5 plDaniels ripMime 1.2.4 plDaniels ripMime 1.2.3 plDaniels ripMime 1.2.2 plDaniels ripMime 1.2.1 plDaniels ripMime 1.2 .0 |
| Not Vulnerable: |
plDaniels ripMime 1.3.2 .3 |
Discussion
ripMIME MIME Attachment Decoding Weakness
It is reported that a weakness exists in ripMIMEs decoding routine.
If ripMIME is being used in conjunction with a virus scanning, or other similar type of application, this weakness has the affect of not passing the attachment to the engine. This means that the attachments will bypass the scanning process.
By bypassing the scanning process, the message may then be passed on to an end user while still containing virus, or other malicious code that should have been blocked by the filter.
Attackers may exploit this weakness by forming malicious content designed to pass through filtering software. This content is designed to be decoded by the end users MUA. Some MUAs may decode the MIME attachments, even though they are formed incorrectly, allowing the malicious content to be delivered.
Version 1.3.2.3 has been released which fixes this weakness.
It is reported that a weakness exists in ripMIMEs decoding routine.
If ripMIME is being used in conjunction with a virus scanning, or other similar type of application, this weakness has the affect of not passing the attachment to the engine. This means that the attachments will bypass the scanning process.
By bypassing the scanning process, the message may then be passed on to an end user while still containing virus, or other malicious code that should have been blocked by the filter.
Attackers may exploit this weakness by forming malicious content designed to pass through filtering software. This content is designed to be decoded by the end users MUA. Some MUAs may decode the MIME attachments, even though they are formed incorrectly, allowing the malicious content to be delivered.
Version 1.3.2.3 has been released which fixes this weakness.
Exploit / POC
ripMIME MIME Attachment Decoding Weakness
No exploit is required.
No exploit is required.
Solution / Fix
ripMIME MIME Attachment Decoding Weakness
Solution:
The vendor has released version 1.3.2.3 addressing this issue.
plDaniels ripMime 1.2 .0
plDaniels ripMime 1.2.1
plDaniels ripMime 1.2.2
plDaniels ripMime 1.2.3
plDaniels ripMime 1.2.4
plDaniels ripMime 1.2.5
plDaniels ripMime 1.2.6
plDaniels ripMime 1.2.7
plDaniels ripMime 1.3.2 .0
plDaniels ripMime 1.3.2 .2
Solution:
The vendor has released version 1.3.2.3 addressing this issue.
plDaniels ripMime 1.2 .0
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.2.1
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.2.2
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.2.3
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.2.4
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.2.5
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.2.6
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.2.7
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.3.2 .0
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
plDaniels ripMime 1.3.2 .2
-
plDaniels ripmime-1.3.2.3.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.3.2.3.tar.gz
References
ripMIME MIME Attachment Decoding Weakness
References:
References:
- ripMIME Changelog (plDaniels)
- ripMime Product Page (plDaniels)