ELM frm Command Remote Buffer Overflow Vulnerability
BID:9430
Info
ELM frm Command Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 9430 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0966 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2004 12:00AM |
| Updated: | Jul 12 2009 02:06AM |
| Credit: | The disclosure of this issue has been credited to phr-redhat <[email protected].. |
| Vulnerable: |
SGI ProPack 2.4 SGI ProPack 2.3 Redhat Linux Advanced Work Station 2.1 Redhat Linux Advanced Server 2.1 Update 2 Redhat Linux 7.3 Redhat Linux 7.2 Redhat Linux 2.1 Elm Development Group ELM 2.5.6 Elm Development Group ELM 2.5.5 Elm Development Group ELM 2.5.3 Elm Development Group ELM 2.5.1 Elm Development Group ELM 2.5 alpha3 Elm Development Group ELM 2.4 Elm Development Group ELM 2.3 |
| Not Vulnerable: | |
Discussion
ELM frm Command Remote Buffer Overflow Vulnerability
It has been reported that ELM e-mail client may be prone to a remote buffer overflow vulnerability. A remote attacker may be able to cause a buffer overrun condition by sending a message with an excessively long header field. Specifically, the issue is presented if the maliciously crafted message is opened by a user via the 'frm' command.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code in the context of the user.
Although unconfirmed, ELM versions 2.5.6 and prior may be vulnerable to this issue.
It has been reported that ELM e-mail client may be prone to a remote buffer overflow vulnerability. A remote attacker may be able to cause a buffer overrun condition by sending a message with an excessively long header field. Specifically, the issue is presented if the maliciously crafted message is opened by a user via the 'frm' command.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code in the context of the user.
Although unconfirmed, ELM versions 2.5.6 and prior may be vulnerable to this issue.
Exploit / POC
ELM frm Command Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ELM frm Command Remote Buffer Overflow Vulnerability
Solution:
SGI has released an advisory 20040202-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Fixes are available below.
RedHat has provided fixes to address this issue in Red Hat Enterprise Linux Advanced Server version 2.1.
SGI has released an advisory 20040103-01-U with fixes to address this and other issues. Please see the referenced advisory for more information.
Redhat Linux Advanced Server 2.1 Update 2
Redhat Linux Advanced Work Station 2.1
SGI ProPack 2.3
SGI ProPack 2.4
Solution:
SGI has released an advisory 20040202-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information. Fixes are available below.
RedHat has provided fixes to address this issue in Red Hat Enterprise Linux Advanced Server version 2.1.
SGI has released an advisory 20040103-01-U with fixes to address this and other issues. Please see the referenced advisory for more information.
Redhat Linux Advanced Server 2.1 Update 2
-
RedHat elm-2.5.6-4.i386.rpm
Update for i386.
ftp://updates.redhat.com/2.1AS/en/os/SRPMS/elm-2.5.6-4.i386.rpm -
RedHat elm-2.5.6-4.ia64.rpm
Update for ia64.
ftp://updates.redhat.com/2.1AS/en/os/SRPMS/elm-2.5.6-4.ia64.rpm
Redhat Linux Advanced Work Station 2.1
-
RedHat elm-2.5.6-4.ia64.rpm
Update for ia64.
ftp://updates.redhat.com/2.1AS/en/os/SRPMS/elm-2.5.6-4.ia64.rpm
SGI ProPack 2.3
-
SGI patch10043.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.3/
SGI ProPack 2.4
-
SGI patch10044.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.4/patch1 0044.tar.gz
References
ELM frm Command Remote Buffer Overflow Vulnerability
References:
References:
- Elm 'frm' Command Buffer Overflow Permits Remote Code Execution (Security Tracker)