Sympa 'Content-Type' Header Remote Denial Of Service Vulnerability
BID:28539
Info
Sympa 'Content-Type' Header Remote Denial Of Service Vulnerability
| Bugtraq ID: | 28539 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1648 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2008 12:00AM |
| Updated: | Jul 07 2008 03:30PM |
| Credit: | Adam Bernstein |
| Vulnerable: |
Sympa Sympa 5.3.4 Sympa Sympa 5.3.3 Sympa Sympa 5.3.2 Sympa Sympa 5.3.1 Sympa Sympa 5.3 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Sympa Sympa 5.4 |
Discussion
Sympa 'Content-Type' Header Remote Denial Of Service Vulnerability
Sympa is prone to a remote denial-of-service vulnerability because it fails to handle specially crafted 'Content-Type' headers.
An attacker can exploit this issue to cause the application to crash. Successful attacks will deny service to legitimate users.
Versions prior to Sympa 5.4 are affected.
Sympa is prone to a remote denial-of-service vulnerability because it fails to handle specially crafted 'Content-Type' headers.
An attacker can exploit this issue to cause the application to crash. Successful attacks will deny service to legitimate users.
Versions prior to Sympa 5.4 are affected.
Exploit / POC
Sympa 'Content-Type' Header Remote Denial Of Service Vulnerability
Attackers can exploit this issue using standard tools.
Attackers can exploit this issue using standard tools.
Solution / Fix
Sympa 'Content-Type' Header Remote Denial Of Service Vulnerability
Solution:
The vendor released Sympa 5.4 to address this issue. Please see the references for more information.
Sympa Sympa 5.3
Sympa Sympa 5.3.1
Sympa Sympa 5.3.2
Sympa Sympa 5.3.3
Sympa Sympa 5.3.4
Solution:
The vendor released Sympa 5.4 to address this issue. Please see the references for more information.
Sympa Sympa 5.3
-
Sympa sympa-5.4.tar.gz
http://freshmeat.net/redir/sympa/10152/url_tgz/sympa-5.4.tar.gz
Sympa Sympa 5.3.1
-
Sympa sympa-5.4.tar.gz
http://freshmeat.net/redir/sympa/10152/url_tgz/sympa-5.4.tar.gz
Sympa Sympa 5.3.2
-
Sympa sympa-5.4.tar.gz
http://freshmeat.net/redir/sympa/10152/url_tgz/sympa-5.4.tar.gz
Sympa Sympa 5.3.3
-
Sympa sympa-5.4.tar.gz
http://freshmeat.net/redir/sympa/10152/url_tgz/sympa-5.4.tar.gz
Sympa Sympa 5.3.4
-
Sympa sympa-5.4.tar.gz
http://freshmeat.net/redir/sympa/10152/url_tgz/sympa-5.4.tar.gz
References
Sympa 'Content-Type' Header Remote Denial Of Service Vulnerability
References:
References:
- Corrupted Content-Type: header causes sympa.pl to crash sending text digest (Adam Bernstein)
- Release notes (Sympa)
- Sympa Home Page (Sympa)