Multiple Vendor IMAP Client Mailbox Size Memory Corruption Vulnerability
BID:7602
Info
Multiple Vendor IMAP Client Mailbox Size Memory Corruption Vulnerability
| Bugtraq ID: | 7602 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0297 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery is credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
University of Washington Pine 4.53 University of Washington Pine 4.52 University of Washington Pine 4.44 University of Washington Pine 4.33 University of Washington Pine 4.30 University of Washington Pine 4.21 University of Washington imap 2002b Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mutt Mutt 1.4.1 Mutt Mutt 1.4 .0 Mutt Mutt 1.3.28 Mutt Mutt 1.3.27 Mutt Mutt 1.3.25 Mutt Mutt 1.3.24 Mutt Mutt 1.3.22 Mutt Mutt 1.3.17 Mutt Mutt 1.3.16 Mutt Mutt 1.3.12 Mutt Mutt 1.2.5 Mutt Mutt 1.2 -1 GNOME Balsa 2.0.10 GNOME Balsa 2.0.6 Avaya Integrated Management Avaya CVLAN |
| Not Vulnerable: |
University of Washington imap 2002c |
Discussion
Multiple Vendor IMAP Client Mailbox Size Memory Corruption Vulnerability
Vulnerabilities have been reported that could cause memory corruption and unpredictable behavior in multiple e-mail clients that support the IMAP protocol.
These issues may occur when the clients handle an excessive value for the mailbox size, as specified by an IMAP server. A malicious IMAP server may potentially leverage this condition to crash affected clients or possibly corrupt memory with specific values. The possibility of arbitrary code execution is not confirmed.
Consequences may vary depending on the particular clients.
Vulnerabilities have been reported that could cause memory corruption and unpredictable behavior in multiple e-mail clients that support the IMAP protocol.
These issues may occur when the clients handle an excessive value for the mailbox size, as specified by an IMAP server. A malicious IMAP server may potentially leverage this condition to crash affected clients or possibly corrupt memory with specific values. The possibility of arbitrary code execution is not confirmed.
Consequences may vary depending on the particular clients.
Exploit / POC
Multiple Vendor IMAP Client Mailbox Size Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor IMAP Client Mailbox Size Memory Corruption Vulnerability
Solution:
This issue has reportedly been addressed in University of Washington imap-2002c. Please contact the vendor to obtain an upgraded version.
Please see the referenced advisories for more information.
Solution:
This issue has reportedly been addressed in University of Washington imap-2002c. Please contact the vendor to obtain an upgraded version.
Please see the referenced advisories for more information.
References
Multiple Vendor IMAP Client Mailbox Size Memory Corruption Vulnerability
References:
References:
- ASA-2005-026 - Vulnerability in pine - (RHSA-2005-015) (Avaya)
- Bugzilla Bug 184074 �?? CAN-2003-0297 c-client/Pine crash (Pavel Kankovsky)
- RHSA-2005:015-05 - Pine (RedHat)
- RHSA-2005:114-06 - imap security update (Red Hat)
- Buffer overflows in multiple IMAP clients (Timo Sirainen
)