MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
BID:5013
Info
MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
| Bugtraq ID: | 5013 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1575 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Credited to sec <[email protected]>. |
| Vulnerable: |
MIT cgiemail 1.6 |
| Not Vulnerable: | |
Discussion
MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
A vulnerability has been reported for cgiemail that allows cgiemail to act as an open relay for email. The vulnerability is due to failure of proper santization of user supplied values. In particular the new line code "%0a" is not filtered properly.
As a result, a malicious user may trivially specify any email address, effectively using the script as an open mail relay.
A vulnerability has been reported for cgiemail that allows cgiemail to act as an open relay for email. The vulnerability is due to failure of proper santization of user supplied values. In particular the new line code "%0a" is not filtered properly.
As a result, a malicious user may trivially specify any email address, effectively using the script as an open mail relay.
Exploit / POC
MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
Solution:
Debian has released advisory DSA 437-1 dealing with this issue:
MIT cgiemail 1.6
Solution:
Debian has released advisory DSA 437-1 dealing with this issue:
MIT cgiemail 1.6
-
Debian cgiemail_1.6-14woody1_alpha.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_alpha.deb -
Debian cgiemail_1.6-14woody1_arm.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_arm.deb -
Debian cgiemail_1.6-14woody1_hppa.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_hppa.deb -
Debian cgiemail_1.6-14woody1_i386.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_i386.deb -
Debian cgiemail_1.6-14woody1_ia64.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_ia64.deb -
Debian cgiemail_1.6-14woody1_m68k.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_m68k.deb -
Debian cgiemail_1.6-14woody1_mips.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_mips.deb -
Debian cgiemail_1.6-14woody1_mipsel.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_mipsel.deb -
Debian cgiemail_1.6-14woody1_powerpc.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_powerpc.deb -
Debian cgiemail_1.6-14woody1_s390.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_s390.deb -
Debian cgiemail_1.6-14woody1_sparc.deb
http://security.debian.org/pool/updates/main/c/cgiemail/cgiemail_1.6-1 4woody1_sparc.deb
References
MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability
References:
References:
- cgiemail Home Page (MIT)
- patch for vulnerability in cgiemail (Matt Riffle
)