Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
BID:18642
CVE-2006-3242 |Info
Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 18642 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3242 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2006 12:00AM |
| Updated: | Sep 04 2006 06:48PM |
| Credit: | TAKAHASHI Tamotsu discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 SGI ProPack 3.0 SP6 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.0 OpenPKG OpenPKG Current Mutt Mutt 1.5.11 Mutt Mutt 1.5.9 Mutt Mutt 1.5.5i Mutt Mutt 1.4.2.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Avaya Interactive Response 1.3 Avaya Interactive Response 1.2.1 Avaya Interactive Response Avaya Integrated Management 2.1 Avaya Integrated Management Avaya CVLAN |
| Not Vulnerable: | |
Discussion
Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
Mutt is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.
Mutt version 1.4.2.1 is reported to be vulnerable. Other versions may be affected as well.
Mutt is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.
Mutt version 1.4.2.1 is reported to be vulnerable. Other versions may be affected as well.
Exploit / POC
Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
Solution:
The vendor has addressed this issue in the latest CVS release. Please see the advisories and contact the vendor for more information.
Mutt Mutt 1.5.5i
Mutt Mutt 1.5.11
Mutt Mutt 1.5.9
OpenPKG OpenPKG 2.0
OpenPKG OpenPKG 2.5
Solution:
The vendor has addressed this issue in the latest CVS release. Please see the advisories and contact the vendor for more information.
Mutt Mutt 1.5.5i
-
Mandriva mutt-1.5.5.1i-2.1.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mutt-1.5.5.1i-2.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mutt-utf8-1.5.5.1i-2.1.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva mutt-utf8-1.5.5.1i-2.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/
Mutt Mutt 1.5.11
-
Ubuntu mutt_1.5.11-3ubuntu2.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.11-3ubuntu 2.1_amd64.deb -
Ubuntu mutt_1.5.11-3ubuntu2.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.11-3ubuntu 2.1_i386.deb -
Ubuntu mutt_1.5.11-3ubuntu2.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.11-3ubuntu 2.1_powerpc.deb -
Ubuntu mutt_1.5.11-3ubuntu2.1_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.11-3ubuntu 2.1_sparc.deb
Mutt Mutt 1.5.9
-
Ubuntu mutt_1.5.11-3ubuntu2.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.11-3ubuntu 2.1_amd64.deb -
Ubuntu mutt_1.5.9-2ubuntu1.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.9-2ubuntu1 .1_amd64.deb -
Ubuntu mutt_1.5.9-2ubuntu1.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.9-2ubuntu1 .1_amd64.deb -
Ubuntu mutt_1.5.9-2ubuntu1.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.9-2ubuntu1 .1_i386.deb -
Ubuntu mutt_1.5.9-2ubuntu1.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.9-2ubuntu1 .1_i386.deb -
Ubuntu mutt_1.5.9-2ubuntu1.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/m/mutt/mutt_1.5.9-2ubuntu1 .1_powerpc.deb
OpenPKG OpenPKG 2.0
-
OpenPKG mutt-1.5.11i-2.20060715
OpenPKG 2-STABLE
ftp://ftp.openpkg.org/release
OpenPKG OpenPKG 2.5
-
OpenPKG mutt-1.5.11i-2.5.1
OpenPKG 2.5
ftp://ftp.openpkg.org/release
References
Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
References:
References:
- Fix browse_get_namespace() (TAKAHASHI Tamotsu
) - Mutt Homepage (Mutt)
- mutt security update (RHSA-2006-0577) (Avaya)
- RHSA-2006:0577-3 - mutt security update (Red Hat)
- rPSA-2006-0116-1 mutt (rPath)