Microsoft Collaboration Data Objects Remote Buffer Overflow Vulnerability
BID:15067
Info
Microsoft Collaboration Data Objects Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 15067 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1987 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Gary O'leary-Steele of Sec-1 reported this issue to the vendor. |
| Vulnerable: |
Nortel Networks Centrex IP Element Manager 8.0 Nortel Networks Centrex IP Element Manager 7.0 Nortel Networks Centrex IP Element Manager 2.5 Nortel Networks Centrex IP Client Manager 8.0 Nortel Networks Centrex IP Client Manager 7.0 Nortel Networks Centrex IP Client Manager 2.5 Nortel Networks Centrex IP Client Manager Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft IIS 6.0 Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft Exchange Server 2000 SP3 Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Collaboration Data Objects Remote Buffer Overflow Vulnerability
Microsoft CDO is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the library to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
This issue presents itself when an attacker sends a specifically crafted email message to an email server utilizing the affected library.
This issue allows remote attackers to execute arbitrary machine code in the context of the application utilizing the library.
Microsoft CDO is susceptible to a remote buffer overflow vulnerability. This issue is due to a failure of the library to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
This issue presents itself when an attacker sends a specifically crafted email message to an email server utilizing the affected library.
This issue allows remote attackers to execute arbitrary machine code in the context of the application utilizing the library.
Exploit / POC
Microsoft Collaboration Data Objects Remote Buffer Overflow Vulnerability
The issue may be triggered by crafting an email with an overly long header name, for example:
Content-Type<LARGE STRING>:
The researcher who discovered this issue has developed working exploit code. This exploit code is not known to be circulating in the wild.
The issue may be triggered by crafting an email with an overly long header name, for example:
Content-Type<LARGE STRING>:
The researcher who discovered this issue has developed working exploit code. This exploit code is not known to be circulating in the wild.
Solution / Fix
Microsoft Collaboration Data Objects Remote Buffer Overflow Vulnerability
Solution:
Nortel Networks has released a technical support bulletin (2005006318) regarding this and other issues for their Centrex IP Client Manager (CICM). They report the vulnerabilities will be fixed in the upcoming 2.5, 7.0 and 8.0 maintenance releases. Please see the referenced bulletin for further information.
Fixes are available:
Microsoft Windows Server 2003 Datacenter Edition SP1
Microsoft Windows Server 2003 Datacenter x64 Edition
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows XP Home SP2
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows XP Media Center Edition SP1
Microsoft Windows Server 2003 Web Edition
Microsoft Windows XP Home SP1
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 Web Edition SP1
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows Server 2003 Standard Edition
Microsoft Exchange Server 2000 SP3
Microsoft Windows XP Professional SP2
Microsoft Windows Server 2003 Datacenter Edition Itanium SP1
Microsoft Windows Server 2003 Standard x64 Edition
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows XP Professional SP1
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Solution:
Nortel Networks has released a technical support bulletin (2005006318) regarding this and other issues for their Centrex IP Client Manager (CICM). They report the vulnerabilities will be fixed in the upcoming 2.5, 7.0 and 8.0 maintenance releases. Please see the referenced bulletin for further information.
Fixes are available:
Microsoft Windows Server 2003 Datacenter Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Windows Server 2003 Datacenter x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5504C410-CDCB -4826-B002-DBA0E3A402A4
Microsoft Windows Server 2003 Enterprise Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Windows XP Media Center Edition SP2
-
Microsoft Security Update for Windows XP (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E0DAF2D1-656C -4580-94C1-8AB009B4AD4F
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=AE0BA6D7-37AF -46E8-9E25-AB63883FA944
Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
-
Microsoft Security Update for Windows Server 2003 Itanium 64-bit Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=956FFD90-60AF -4296-8765-F0A17A77DB77
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Windows XP Home SP2
-
Microsoft Security Update for Windows XP (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E0DAF2D1-656C -4580-94C1-8AB009B4AD4F
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=AE0BA6D7-37AF -46E8-9E25-AB63883FA944
Microsoft Windows XP Media Center Edition SP1
-
Microsoft Security Update for Windows XP (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E0DAF2D1-656C -4580-94C1-8AB009B4AD4F
Microsoft Windows Server 2003 Web Edition
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E0DAF2D1-656C -4580-94C1-8AB009B4AD4F
Microsoft Windows XP Professional x64 Edition
-
Microsoft Security Update for Windows XP x64 Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=D389EF4D-583D -41C0-9081-844D348F3817
Microsoft Windows Server 2003 Web Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 Itanium 64-bit Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=956FFD90-60AF -4296-8765-F0A17A77DB77
Microsoft Windows Server 2003 Standard Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=1BC06799-B9F5 -416F-8965-DC0E07A24A29
Microsoft Exchange Server 2000 SP3
-
Microsoft Security Update for Exchange 2000 Server (KB906780)
http://www.microsoft.com/downloads/details.aspx?FamilyId=60FD0DDC-04B7 -4879-930B-53375823CD51
Microsoft Windows XP Professional SP2
-
Microsoft Security Update for Windows XP (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E0DAF2D1-656C -4580-94C1-8AB009B4AD4F
Microsoft Windows Server 2003 Datacenter Edition Itanium SP1
-
Microsoft Security Update for Windows Server 2003 Itanium 64-bit Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=956FFD90-60AF -4296-8765-F0A17A77DB77
Microsoft Windows Server 2003 Standard x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5504C410-CDCB -4826-B002-DBA0E3A402A4
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=AE0BA6D7-37AF -46E8-9E25-AB63883FA944
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=AE0BA6D7-37AF -46E8-9E25-AB63883FA944
Microsoft Windows Server 2003 Enterprise x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5504C410-CDCB -4826-B002-DBA0E3A402A4
Microsoft Windows XP Professional SP1
-
Microsoft Security Update for Windows XP (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E0DAF2D1-656C -4580-94C1-8AB009B4AD4F
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 Itanium 64-bit Edition (KB901017)
http://www.microsoft.com/downloads/details.aspx?FamilyId=956FFD90-60AF -4296-8765-F0A17A77DB77
References
Microsoft Collaboration Data Objects Remote Buffer Overflow Vulnerability
References:
References:
- Centrex IP Client Manager (CICM) response to Microsoft October security bulletin (Nortel Networks)
- Microsoft Security Bulletin MS05-048 (Microsoft)
- reuse (Microsoft)
- [SEC-1 Advisory] Collaboration Data Objects Buffer Overflow Vulnerability ("Gary Oleary-Steele"
)