Courier-IMAP Remote Format String Vulnerability
BID:10976
Info
Courier-IMAP Remote Format String Vulnerability
| Bugtraq ID: | 10976 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0777 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2004 12:00AM |
| Updated: | Jul 12 2009 06:17AM |
| Credit: | An anonymous person disclosed this vulnerability. |
| Vulnerable: |
Inter7 Courier-IMAP 3.0.2 r1 Inter7 Courier-IMAP 3.0.2 Inter7 Courier-IMAP 3.0.1 Inter7 Courier-IMAP 3.0 .0 Inter7 Courier-IMAP 2.2.1 Inter7 Courier-IMAP 2.2 .0 Inter7 Courier-IMAP 2.1.2 Inter7 Courier-IMAP 2.1.1 Inter7 Courier-IMAP 2.1 Inter7 Courier-IMAP 2.0 .0 Inter7 Courier-IMAP 1.7 Inter7 Courier-IMAP 1.6 |
| Not Vulnerable: |
Double Precision Incorporated Courier-IMAP 3.0.7 |
Discussion
Courier-IMAP Remote Format String Vulnerability
Courier-IMAP is reported to be susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the user that the IMAP daemon runs as. This vulnerability is exploitable prior to authentication.
Courier-IMAP versions 1.6.0 through to 2.2.1 are reported vulnerable. Other versions may also be vulnerable.
Courier-IMAP is reported to be susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the user that the IMAP daemon runs as. This vulnerability is exploitable prior to authentication.
Courier-IMAP versions 1.6.0 through to 2.2.1 are reported vulnerable. Other versions may also be vulnerable.
Exploit / POC
Courier-IMAP Remote Format String Vulnerability
Exploit code has been provided by ktha <[email protected]>:
Exploit code has been provided by ktha <[email protected]>:
Solution / Fix
Courier-IMAP Remote Format String Vulnerability
Solution:
The vendor has released version 3.0.7 of the software addressing this issue. Users of affected packages are urged to upgrade.
Gentoo has released an advisory (GLSA 200408-19) to address this issue. Please see the referenced advisory for more information. Gentoo users can update their computers by carrying out the following commands:
emerge sync
emerge -pv ">=net-mail/courier-imap-3.0.5"
emerge ">=net-mail/courier-imap-3.0.5"
Please see the referenced Gentoo advisory for more information.
Trustix Linux has released advisory TSL-2004-0043 dealing with this and other issues. Please see the referenced advisory for more information.
Inter7 Courier-IMAP 1.6
Inter7 Courier-IMAP 1.7
Inter7 Courier-IMAP 2.0 .0
Inter7 Courier-IMAP 2.1
Inter7 Courier-IMAP 2.1.1
Inter7 Courier-IMAP 2.1.2
Inter7 Courier-IMAP 2.2 .0
Inter7 Courier-IMAP 2.2.1
Inter7 Courier-IMAP 3.0 .0
Inter7 Courier-IMAP 3.0.1
Solution:
The vendor has released version 3.0.7 of the software addressing this issue. Users of affected packages are urged to upgrade.
Gentoo has released an advisory (GLSA 200408-19) to address this issue. Please see the referenced advisory for more information. Gentoo users can update their computers by carrying out the following commands:
emerge sync
emerge -pv ">=net-mail/courier-imap-3.0.5"
emerge ">=net-mail/courier-imap-3.0.5"
Please see the referenced Gentoo advisory for more information.
Trustix Linux has released advisory TSL-2004-0043 dealing with this and other issues. Please see the referenced advisory for more information.
Inter7 Courier-IMAP 1.6
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
Inter7 Courier-IMAP 1.7
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2 -
Trustix courier-imap-1.7.1-15tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix courier-imap-ldap-1.7.1-15tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix courier-imap-mysql-1.7.1-15tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix courier-imap-pgsql-1.7.1-15tr.i586.rpm
Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/
Inter7 Courier-IMAP 2.0 .0
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
Inter7 Courier-IMAP 2.1
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
Inter7 Courier-IMAP 2.1.1
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
Inter7 Courier-IMAP 2.1.2
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
Inter7 Courier-IMAP 2.2 .0
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
Inter7 Courier-IMAP 2.2.1
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2 -
Trustix courier-imap-2.2.1-5tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix courier-imap-ldap-2.2.1-5tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix courier-imap-mysql-2.2.1-5tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix courier-imap-pgsql-2.2.1-5tr.i586.rpm
Enterprise Server 2 & Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/
Inter7 Courier-IMAP 3.0 .0
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
Inter7 Courier-IMAP 3.0.1
-
Double Precision Incorporated courier-imap-3.0.7.tar.bz2
http://prdownloads.sourceforge.net/courier/courier-imap-3.0.7.tar.bz2
References
Courier-IMAP Remote Format String Vulnerability
References:
References:
- Courier-IMAP Home Page (Double Precision Inc.)
- Courier-IMAP Remote Format String Vulnerability (iDEFENSE)
- Courier-MTA (Double Precision Inc.)