Multiple Vendor MIME Encapsulation Content Checking Filter Bypass Vulnerabilities
BID:11157
Info
Multiple Vendor MIME Encapsulation Content Checking Filter Bypass Vulnerabilities
| Bugtraq ID: | 11157 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-1014 CVE-2003-1015 CVE-2003-1016 CVE-2004-0051 CVE-2004-0052 CVE-2004-0053 CVE-2004-0161 CVE-2004-0162 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery is credited to Martin O'Neal of Corsaire Security. |
| Vulnerable: |
plDaniels ripMime 1.3.2 .3 plDaniels ripMime 1.3.2 .2 plDaniels ripMime 1.3.2 .0 plDaniels ripMime 1.2.7 plDaniels ripMime 1.2.6 plDaniels ripMime 1.2.5 plDaniels ripMime 1.2.4 plDaniels ripMime 1.2.3 plDaniels ripMime 1.2.2 plDaniels ripMime 1.2.1 plDaniels ripMime 1.2 .0 F-Secure Internet Gatekeeper 6.40 0 F-Secure Internet Gatekeeper 6.32 F-Secure Internet Gatekeeper 6.31 F-Secure Internet Gatekeeper 6.3 Clearswift MailSweeper 4.3.15 Clearswift MailSweeper 4.3.14 Clearswift MailSweeper 4.3.13 Clearswift MailSweeper 4.3.11 Clearswift MailSweeper 4.3.10 Clearswift MailSweeper 4.3.8 Clearswift MailSweeper 4.3.7 |
| Not Vulnerable: |
plDaniels ripMime 1.4 .0.0 |
Discussion
Multiple Vendor MIME Encapsulation Content Checking Filter Bypass Vulnerabilities
Multiple filter bypass vulnerabilities have been reported in numerous software implementations due to ambiguities in MIME encapsulation standards (RFCs 822, and 2045 through 2049).
The following types of software may be impacted by these issues:
- Email clients
- Web clients
- Antivirus products
- Email content filters
- Web content filters
The source of the problem is that affected implementations may not handle malformed or incorrect MIME encapsulated data. As a result, various MIME encapsulation techniques could be used to allow MIME attachments to pass on through when they should be rejected due to being malformed or incorrect. This could have various consequences depending on the implementation, but will also generally require that the client receiving the attachment will be able to interpret the malformed attachment.
A conclusive list of affected implementations is not available at this time. This BID will be updated as more vendor products are determined to be vulnerable.
Multiple filter bypass vulnerabilities have been reported in numerous software implementations due to ambiguities in MIME encapsulation standards (RFCs 822, and 2045 through 2049).
The following types of software may be impacted by these issues:
- Email clients
- Web clients
- Antivirus products
- Email content filters
- Web content filters
The source of the problem is that affected implementations may not handle malformed or incorrect MIME encapsulated data. As a result, various MIME encapsulation techniques could be used to allow MIME attachments to pass on through when they should be rejected due to being malformed or incorrect. This could have various consequences depending on the implementation, but will also generally require that the client receiving the attachment will be able to interpret the malformed attachment.
A conclusive list of affected implementations is not available at this time. This BID will be updated as more vendor products are determined to be vulnerable.
Exploit / POC
Multiple Vendor MIME Encapsulation Content Checking Filter Bypass Vulnerabilities
Corsaire Security have developed test suites to exploit these issues. It is not known if these test suites are publicly available.
Corsaire Security have developed test suites to exploit these issues. It is not known if these test suites are publicly available.
Solution / Fix
Multiple Vendor MIME Encapsulation Content Checking Filter Bypass Vulnerabilities
Solution:
plDaniels have released ripMime 1.4.0.0 to address this issue.
F-Secure will be releasing Internet Gatekeeper 6.41 to address this issue in Q4/04.
plDaniels ripMime 1.2 .0
plDaniels ripMime 1.2.1
plDaniels ripMime 1.2.2
plDaniels ripMime 1.2.3
plDaniels ripMime 1.2.4
plDaniels ripMime 1.2.5
plDaniels ripMime 1.2.6
plDaniels ripMime 1.2.7
plDaniels ripMime 1.3.2 .3
plDaniels ripMime 1.3.2 .0
plDaniels ripMime 1.3.2 .2
Solution:
plDaniels have released ripMime 1.4.0.0 to address this issue.
F-Secure will be releasing Internet Gatekeeper 6.41 to address this issue in Q4/04.
plDaniels ripMime 1.2 .0
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.2.1
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.2.2
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.2.3
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.2.4
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.2.5
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.2.6
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.2.7
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.3.2 .3
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.3.2 .0
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
plDaniels ripMime 1.3.2 .2
-
plDaniels ripmime-1.4.0.0.tar.gz
http://www.pldaniels.com/ripmime/ripmime-1.4.0.0.tar.gz
References
Multiple Vendor MIME Encapsulation Content Checking Filter Bypass Vulnerabilities
References:
References:
- [threatnews] MAILsweeper and NISCC Vulnerability Advisory 380375/MIME (Clearswift)
- Corsaire Advisories (Corsaire)
- Multiple vendor MIME Content-Transfer-Encoding mechanism issue (Corsaire)
- Multiple vendor MIME field multiple occurrence issue (Corsaire)
- Multiple vendor MIME field quoting issue (Corsaire)
- Multiple vendor MIME field whitespace issue (Corsaire)
- Multiple vendor MIME RFC2047 encoding issue (Corsaire)
- Multiple vendor MIME RFC2231 encoding issue (Corsaire)
- Multiple vendor MIME RFC822 comment issue (Corsaire)
- Multiple vendor MIME separator issue (Corsaire)
- NISCC Vulnerability Advisory 380375/MIME (NISCC)