Elm Message-ID Buffer Overflow Vulnerability
BID:3037
Info
Elm Message-ID Buffer Overflow Vulnerability
| Bugtraq ID: | 3037 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2001 12:00AM |
| Updated: | Jul 03 2001 12:00AM |
| Credit: | Reported by [email protected] and posted in a RedHat Security Advisory on July 3, 2001. |
| Vulnerable: |
Elm Development Group ELM 2.5.3 Elm Development Group ELM 2.5.1 Elm Development Group ELM 2.4 |
| Not Vulnerable: |
Elm Development Group ELM 2.5.5 |
Discussion
Elm Message-ID Buffer Overflow Vulnerability
Elm is a mail user agent designed for use with UNIX based operating systems.
The 'elm' program contains a potential buffer overflow vulnerability in its handling of 'Message-ID' fields in e-mail headers. The condition may occur if the field value is of an excessive length.
It may be possible for a remote attacker to exploit this to cause neighbouring memory to be overwritten with arbitrary data. This may lead to the execution of arbitrary code on the system of the user running elm.
Elm is a mail user agent designed for use with UNIX based operating systems.
The 'elm' program contains a potential buffer overflow vulnerability in its handling of 'Message-ID' fields in e-mail headers. The condition may occur if the field value is of an excessive length.
It may be possible for a remote attacker to exploit this to cause neighbouring memory to be overwritten with arbitrary data. This may lead to the execution of arbitrary code on the system of the user running elm.
Exploit / POC
Elm Message-ID Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Elm Message-ID Buffer Overflow Vulnerability
Solution:
Vendor-supplied updates that rectify this issue are available:
Elm Development Group ELM 2.4
Elm Development Group ELM 2.5.3
Solution:
Vendor-supplied updates that rectify this issue are available:
Elm Development Group ELM 2.4
-
RedHat 5.2 alpha elm-2.5.5-0.52.alpha.rpm
ftp://updates.redhat.com/5.2/en/os/alpha/elm-2.5.5-0.52.alpha.rpm -
RedHat 5.2 i386 elm-2.5.5-0.52.i386.rpm
ftp://updates.redhat.com/5.2/en/os/i386/elm-2.5.5-0.52.i386.rpm -
RedHat 5.2 sparc elm-2.5.5-0.52.sparc.rpm
ftp://updates.redhat.com/5.2/en/os/sparc/elm-2.5.5-0.52.sparc.rpm
Elm Development Group ELM 2.5.3
-
Mandrake 1.0.1 i586 elm-2.5.5-1.2mdk.i586.rpm
ftp://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/1.0.1/RPMS /elm-2.5.5-1.2mdk.i586.rpm -
Mandrake 7.1 i586 elm-2.5.5-1.2mdk.i586.rpm
ftp://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/7.1/RPMS/e lm-2.5.5-1.2mdk.i586.rpm -
Mandrake 7.2 i586 elm-2.5.5-1.1mdk.i586.rpm
ftp://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/7.2/RPMS/e lm-2.5.5-1.1mdk.i586.rpm -
Mandrake 8.0 i586 elm-2.5.5-1.1mdk.i586.rpm
ftp://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/8.0/RPMS/e lm-2.5.5-1.1mdk.i586.rpm -
RedHat 6.2 alpha elm-2.5.5-0.62.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/elm-2.5.5-0.62.alpha.rpm -
RedHat 6.2 i386 elm-2.5.5-0.62.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/elm-2.5.5-0.62.i386.rpm -
RedHat 6.2 sparc elm-2.5.5-0.62.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/elm-2.5.5-0.62.sparc.rpm -
RedHat 7.0 alpha elm-2.5.5-1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/elm-2.5.5-1.alpha.rpm -
RedHat 7.0 i386 elm-2.5.5-1.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/elm-2.5.5-1.i386.rpm -
RedHat 7.1 i386 elm-2.5.5-1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/elm-2.5.5-1.i386.rpm -
RedHat 7.1 ia64 elm-2.5.5-1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/elm-2.5.5-1.ia64.rpm