Multiple Vendors Email Clients DNS prefetching Domain Name Information Disclosure Vulnerability
BID:38046
Info
Multiple Vendors Email Clients DNS prefetching Domain Name Information Disclosure Vulnerability
| Bugtraq ID: | 38046 |
| Class: | Design Error |
| CVE: |
CVE-2010-0464 CVE-2010-0463 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2010 12:00AM |
| Updated: | Apr 13 2015 08:36PM |
| Credit: | Mike Cardwell |
| Vulnerable: |
Round Cube RoundCube Webmail 0.3.1 Round Cube RoundCube Webmail 0.2.2 Round Cube RoundCube Webmail 0.3 stable Round Cube RoundCube Webmail 0.2-stable Round Cube RoundCube Webmail 0.2-3 beta Round Cube RoundCube Webmail 0.2-1 alpha Round Cube RoundCube Webmail 0.1rc2 Round Cube Round Cube Webmail 0.1 -20051021 Round Cube Round Cube Webmail 0.1-beta2 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Horde Project IMP 4.3.4 Horde Project IMP 4.3.3 Horde Project IMP 4.3.2 Horde Project IMP 4.2.2 Horde Project IMP 4.2.1 Horde Project IMP 4.1.5 Horde Project IMP 4.1.4 Horde Project IMP 4.0.4 Horde Project IMP 4.0.3 Horde Project IMP 4.0.2 Horde Project IMP 4.0.1 Horde Project IMP 4.0 Horde Project IMP 3.2.6 Horde Project IMP 3.2.5 Horde Project IMP 3.2.4 Horde Project IMP 3.2.3 Horde Project IMP 3.2.2 Horde Project IMP 3.2.1 Horde Project IMP 3.2 Horde Project IMP 3.1.2 Horde Project IMP 3.1 Horde Project IMP 3.0 |
| Not Vulnerable: |
Round Cube RoundCube Webmail 0.4-beta |
Discussion
Multiple Vendors Email Clients DNS prefetching Domain Name Information Disclosure Vulnerability
Web-based email clients from multiple vendors are prone to an information-disclosure vulnerability.
Attackers can exploit this issue to determine the network location of a user. Successful exploits may lead to further attacks.
Update (April 5, 2010): The fix for Horde IMP may be inadequate for some browsers or browser configurations.
Web-based email clients from multiple vendors are prone to an information-disclosure vulnerability.
Attackers can exploit this issue to determine the network location of a user. Successful exploits may lead to further attacks.
Update (April 5, 2010): The fix for Horde IMP may be inadequate for some browsers or browser configurations.
Exploit / POC
Multiple Vendors Email Clients DNS prefetching Domain Name Information Disclosure Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Multiple Vendors Email Clients DNS prefetching Domain Name Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Round Cube RoundCube Webmail 0.2-stable
MandrakeSoft Enterprise Server 5 x86_64
Round Cube RoundCube Webmail 0.3 stable
Round Cube RoundCube Webmail 0.2-3 beta
MandrakeSoft Enterprise Server 5
Round Cube RoundCube Webmail 0.2-1 alpha
Round Cube Round Cube Webmail 0.1-beta2
Round Cube RoundCube Webmail 0.1rc2
Round Cube Round Cube Webmail 0.1 -20051021
Round Cube RoundCube Webmail 0.2.2
Round Cube RoundCube Webmail 0.3.1
Solution:
Updates are available. Please see the references for more information.
Round Cube RoundCube Webmail 0.2-stable
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva roundcubemail-0.2.2-0.2mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
Round Cube RoundCube Webmail 0.3 stable
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
Round Cube RoundCube Webmail 0.2-3 beta
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
MandrakeSoft Enterprise Server 5
-
Mandriva roundcubemail-0.2.2-0.2mdvmes5.noarch.rpm
http://www.mandriva.com/en/download/
Round Cube RoundCube Webmail 0.2-1 alpha
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
Round Cube Round Cube Webmail 0.1-beta2
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
Round Cube RoundCube Webmail 0.1rc2
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
Round Cube Round Cube Webmail 0.1 -20051021
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
Round Cube RoundCube Webmail 0.2.2
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
Round Cube RoundCube Webmail 0.3.1
-
Round Cube disable-dns-prefetch.diff
http://trac.roundcube.net/attachment/ticket/1486449/disable-dns-prefet ch.diff
References
Multiple Vendors Email Clients DNS prefetching Domain Name Information Disclosure Vulnerability
References:
References:
- [#8836] Signal the browser to turn off DNS prefetching when displaying untrusted (Horde)
- CVE-2010-0463 incomplete horde fixes (Nico Golde)
- DNS Pre-fetch Exposure on Thunderbird and Webmail (Mike Cardwell)
- RoundCube should ask browsers to disable DNS prefetching to protect user privacy (trisk)
- RoundCube Webmail Homepage (RoundCube)