Metamail Message Processing Remote Buffer Overflow Vulnerability
BID:16611
Info
Metamail Message Processing Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 16611 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0709 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2006 12:00AM |
| Updated: | Mar 19 2015 09:27AM |
| Credit: | Discovered by Ulf Harnhammar <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Desktop 1.0 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Metamail Metamail 2.7 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Metamail Message Processing Remote Buffer Overflow Vulnerability
Metamail is prone to a remote buffer-overflow vulnerability.
This issue arises when the application handles messages with large string values for boundaries.
This can cause memory corruption and trigger a crash in the application. This issue may also lead to arbitrary code execution, but this is unconfirmed.
Metamail 2.7 is reportedly vulnerable, but other versions may be affected as well.
Metamail is prone to a remote buffer-overflow vulnerability.
This issue arises when the application handles messages with large string values for boundaries.
This can cause memory corruption and trigger a crash in the application. This issue may also lead to arbitrary code execution, but this is unconfirmed.
Metamail 2.7 is reportedly vulnerable, but other versions may be affected as well.
Exploit / POC
Metamail Message Processing Remote Buffer Overflow Vulnerability
A proof of concept is available from the following location:
http://bugs.debian.org/cgi-bin/bugreport.cgi/metamail.txt?bug=352482;msg=5;att=1
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
A proof of concept is available from the following location:
http://bugs.debian.org/cgi-bin/bugreport.cgi/metamail.txt?bug=352482;msg=5;att=1
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Metamail Message Processing Remote Buffer Overflow Vulnerability
Solution:
A patch by Ulf Harnhammar <[email protected]> is available at the following location:
http://bugs.debian.org/cgi-bin/bugreport.cgi/metamail.boundarycrash.patch?bug=352482;msg=5;att=2
Symantec has not verified this patch.
Please see the referenced vendor advisories for more information and fixes.
Metamail Metamail 2.7
Solution:
A patch by Ulf Harnhammar <[email protected]> is available at the following location:
http://bugs.debian.org/cgi-bin/bugreport.cgi/metamail.boundarycrash.patch?bug=352482;msg=5;att=2
Symantec has not verified this patch.
Please see the referenced vendor advisories for more information and fixes.
Metamail Metamail 2.7
-
Debian metamail_2.7-45woody.4_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_alpha.deb -
Debian metamail_2.7-45woody.4_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_arm.deb -
Debian metamail_2.7-45woody.4_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_hppa.deb -
Debian metamail_2.7-45woody.4_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_i386.deb -
Debian metamail_2.7-45woody.4_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_ia64.deb -
Debian metamail_2.7-45woody.4_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_m68k.deb -
Debian metamail_2.7-45woody.4_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_mips.deb -
Debian metamail_2.7-45woody.4_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_mipsel.deb -
Debian metamail_2.7-45woody.4_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_powerpc.deb -
Debian metamail_2.7-45woody.4_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_s390.deb -
Debian metamail_2.7-45woody.4_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 5woody.4_sparc.deb -
Debian metamail_2.7-47sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_alpha.deb -
Debian metamail_2.7-47sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_amd64.deb -
Debian metamail_2.7-47sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_arm.deb -
Debian metamail_2.7-47sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_hppa.deb -
Debian metamail_2.7-47sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_i386.deb -
Debian metamail_2.7-47sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_ia64.deb -
Debian metamail_2.7-47sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_m68k.deb -
Debian metamail_2.7-47sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_mips.deb -
Debian metamail_2.7-47sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_mipsel.deb -
Debian metamail_2.7-47sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_powerpc.deb -
Debian metamail_2.7-47sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_s390.deb -
Debian metamail_2.7-47sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/metamail/metamail_2.7-4 7sarge1_sparc.deb
References
Metamail Message Processing Remote Buffer Overflow Vulnerability
References:
References: