Multiple IMAP Client Integer Overflow Vulnerabilities
BID:7603
Info
Multiple IMAP Client Integer Overflow Vulnerabilities
| Bugtraq ID: | 7603 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0297 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery is credited to Timo Sirainen <[email protected]>. |
| Vulnerable: |
Ximian Evolution 1.2.4 University of Washington Pine 4.53 University of Washington imap 2002b Sylpheed Sylpheed 0.8.11 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Qualcomm Eudora 5.2.1 Mozilla Browser 1.4 a Mozilla Browser 1.3 Microsoft Outlook Express 6.0 Avaya Integrated Management Avaya CVLAN |
| Not Vulnerable: |
Ximian Evolution 1.3.2 (beta) University of Washington imap 2002c Mozilla Browser 1.4 b Mozilla Browser 1.3.1 |
Discussion
Multiple IMAP Client Integer Overflow Vulnerabilities
Multiple IMAP Clients have been reported vulnerable to unspecified integer-overflow vulnerabilities.
The affected IMAP clients reportedly fail to ensure that proper boundary checks are performed on literal size values supplied by a malicious IMAP server. This may result in the manifestation of several variations of integer-overflow vulnerabilities when 'malloc()' tries to allocate memory.
This BID is a multiple vendor alert. Each affected implementation will be given a separate BID with vendor-specific details when further analysis of these issues is complete; this BID will then be retired.
Multiple IMAP Clients have been reported vulnerable to unspecified integer-overflow vulnerabilities.
The affected IMAP clients reportedly fail to ensure that proper boundary checks are performed on literal size values supplied by a malicious IMAP server. This may result in the manifestation of several variations of integer-overflow vulnerabilities when 'malloc()' tries to allocate memory.
This BID is a multiple vendor alert. Each affected implementation will be given a separate BID with vendor-specific details when further analysis of these issues is complete; this BID will then be retired.
Exploit / POC
Multiple IMAP Client Integer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Multiple IMAP Client Integer Overflow Vulnerabilities
Solution:
Reportedly, this issue has been addressed in University of Washington imap-2002c, Ximian Evolution 1.3.2 (beta), and Mozilla 1.3.1 and 1.4b. Please contact the appropriate vendor to obtain an upgraded version.
Please see the referenced advisories for further information.
Solution:
Reportedly, this issue has been addressed in University of Washington imap-2002c, Ximian Evolution 1.3.2 (beta), and Mozilla 1.3.1 and 1.4b. Please contact the appropriate vendor to obtain an upgraded version.
Please see the referenced advisories for further information.
References
Multiple IMAP Client Integer Overflow Vulnerabilities
References:
References:
- ASA-2005-026 - Vulnerability in pine - (RHSA-2005-015) (Avaya)
- RHSA-2005:015-05 - Pine (RedHat)
- RHSA-2005:114-06 - imap security update (Red Hat)
- Buffer overflows in multiple IMAP clients (Timo Sirainen
)