Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vulnerability
BID:29705
Info
Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vulnerability
| Bugtraq ID: | 29705 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-2711 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2008 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | Matthias Andree reported this issue. Petr Uzel, Petr Cerny, and Gunter Nau are credited with discovering and researching the problem. |
| Vulnerable: |
Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. openSUSE 10.3 rPath rPath Linux 2 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Desktop 3.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Eric Raymond Fetchmail 6.3.8 Eric Raymond Fetchmail 6.3.7 Eric Raymond Fetchmail 6.3.6 Eric Raymond Fetchmail 6.3.5 Eric Raymond Fetchmail 6.3.4 Eric Raymond Fetchmail 6.3.3 Eric Raymond Fetchmail 6.3.2 Eric Raymond Fetchmail 6.3.1 Eric Raymond Fetchmail 6.3 Eric Raymond Fetchmail 6.2.5 Eric Raymond Fetchmail 4.6.8 Eric Raymond Fetchmail 4.6.7 Eric Raymond Fetchmail 6.3.6-rc3 Eric Raymond Fetchmail 6.3.6-rc2 Eric Raymond Fetchmail 6.3.6-rc1 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Eric Raymond Fetchmail 6.3.9 |
Discussion
Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vulnerability
Fetchmail is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of the issue, remote code execution may also be possible, but this has not been confirmed.
Versions prior to Fetchmail 6.3.9 are vulnerable.
Fetchmail is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of the issue, remote code execution may also be possible, but this has not been confirmed.
Versions prior to Fetchmail 6.3.9 are vulnerable.
Exploit / POC
Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vulnerability
An attacker may trigger this issue by constructing a specially crafted email message and enticing an unsuspecting victim to interact with the application in verbose mode.
An attacker may trigger this issue by constructing a specially crafted email message and enticing an unsuspecting victim to interact with the application in verbose mode.
Solution / Fix
Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.6
Apple Mac OS X Server 10.5.6
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.4.11
-
Apple SecUpd2009-001Intel.dmg
for Intel
http://support.apple.com/downloads/Security_Update_2009_001__Tiger_Int el_ -
Apple SecUpd2009-001PPC.dmg
for PPC
http://support.apple.com/downloads/Security_Update_2009_001__Tiger_PPC _
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2009-001PPC.dmg
for PPC
http://support.apple.com/downloads/Security_Update_2009_001__Server_Ti ger_PPC_ -
Apple SecUpdSrvr2009-001Univ.dmg
Universal
http://support.apple.com/downloads/Security_Update_2009_001__Server_Un iversal_
Apple Mac OS X 10.5.6
-
Apple SecUpd2009-001.dmg
http://support.apple.com/downloads/Security_Update_2009_001__Leopard_
Apple Mac OS X Server 10.5.6
-
Apple SecUpdSrvr2009-001.dmg
http://support.apple.com/downloads/Security_Update_2009_001__Server_Le opard_
References
Fetchmail Verbose Mode Large Log Messages Remote Denial of Service Vulnerability
References:
References:
- Bug 354291 - fetchmail Segmentation fault (Novell)
- Fetchmail Home Page (Fetchmail)
- fetchmail REVISED security announcement fetchmail-SA-2008-01 (CVE-2008-2711) ([email protected])
- fetchmail security announcement fetchmail-SA-2008-01 (CVE-2008-2711) ([email protected])
- fetchmail-SA-2008-01: Crash on large log messages in verbose mode (Matthias Andree )