Courier Multiple Remote Buffer Overflow Vulnerabilities
BID:9845
Info
Courier Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 9845 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0224 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
Inter7 Courier-IMAP 2.2.1 Inter7 Courier-IMAP 2.2 .0 Inter7 Courier-IMAP 2.1.2 Inter7 Courier-IMAP 2.1.1 Inter7 Courier-IMAP 2.1 Inter7 Courier-IMAP 2.0 .0 Inter7 Courier-IMAP 1.7 Inter7 Courier-IMAP 1.6 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Double Precision Incorporated SqWebMail 3.6.2 Double Precision Incorporated SqWebMail 3.6.1 Double Precision Incorporated SqWebMail 3.6 .0 Double Precision Incorporated SqWebMail 3.5.3 Double Precision Incorporated SqWebMail 3.5.2 Double Precision Incorporated Courier MTA 0.44.2 Double Precision Incorporated Courier MTA 0.44 Double Precision Incorporated Courier MTA 0.43.2 Double Precision Incorporated Courier MTA 0.43.1 Double Precision Incorporated Courier MTA 0.43 Double Precision Incorporated Courier MTA 0.42.2 Double Precision Incorporated Courier MTA 0.40.1 Double Precision Incorporated Courier MTA 0.40 Double Precision Incorporated Courier MTA 0.38.1 Double Precision Incorporated Courier MTA 0.37.3 |
| Not Vulnerable: |
Inter7 Courier-IMAP 3.0.1 Inter7 Courier-IMAP 3.0 .0 Double Precision Incorporated SqWebMail 4.0.1 Double Precision Incorporated SqWebMail 4.0 .0 Double Precision Incorporated Courier MTA 0.45.1 Double Precision Incorporated Courier MTA 0.45 |
Discussion
Courier Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflow vulnerabilities have been identified in Courier MTA, Courier SqWebMail, and Courier-IMAP. These vulnerabilities may allow a remote attacker to execute arbitrary code on a vulnerable system in order to gain unauthorized access.
The issues exist in the 'SHIFT_JIS' converter in 'shiftjis.c' and 'ISO2022JP' converter in 'so2022jp.c'. An attacker may be able to exploit these issues by supplying Unicode characters that exceed BMP (Basic Multilingual Plane) range.
These issues have been reported to affect Courier MTA 0.44.2 and prior, Courier-IMAP 2.2.1 and prior, and Courier SqWebMail 3.6.2 and prior. It has also been reported that the vulnerable codeset mappings may be employed by the Courier IMAP and Webmail service, however, they are not enabled by default.
These issues are being further analyzed and this BID will be updated once analysis is complete.
Multiple buffer overflow vulnerabilities have been identified in Courier MTA, Courier SqWebMail, and Courier-IMAP. These vulnerabilities may allow a remote attacker to execute arbitrary code on a vulnerable system in order to gain unauthorized access.
The issues exist in the 'SHIFT_JIS' converter in 'shiftjis.c' and 'ISO2022JP' converter in 'so2022jp.c'. An attacker may be able to exploit these issues by supplying Unicode characters that exceed BMP (Basic Multilingual Plane) range.
These issues have been reported to affect Courier MTA 0.44.2 and prior, Courier-IMAP 2.2.1 and prior, and Courier SqWebMail 3.6.2 and prior. It has also been reported that the vulnerable codeset mappings may be employed by the Courier IMAP and Webmail service, however, they are not enabled by default.
These issues are being further analyzed and this BID will be updated once analysis is complete.
Exploit / POC
Courier Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Courier Multiple Remote Buffer Overflow Vulnerabilities
Solution:
The vendor has released Courier MTA 0.45, Courier-IMAP 3.0.0, and SqWebMail 4.0.0 to address these issues.
Gentoo have released an advisory (GLSA 200403-06) and updates to address this issue. Gentoo users are advised to upgrade to current packages by emerging the updated packages as follows:
# emerge sync
And depending on your installation:
# emerge -pv ">=net-mail/courier-imap-3.0.0"
# emerge ">=net-mail/courier-imap-3.0.0"
Or:
# emerge -pv ">=net-mail/courier-0.45"
# emerge ">=net-mail/courier-0.45"
Double Precision Incorporated Courier MTA 0.37.3
Double Precision Incorporated Courier MTA 0.38.1
Double Precision Incorporated Courier MTA 0.40
Double Precision Incorporated Courier MTA 0.40.1
Double Precision Incorporated Courier MTA 0.42.2
Double Precision Incorporated Courier MTA 0.43
Double Precision Incorporated Courier MTA 0.43.1
Double Precision Incorporated Courier MTA 0.43.2
Double Precision Incorporated Courier MTA 0.44
Double Precision Incorporated Courier MTA 0.44.2
Inter7 Courier-IMAP 1.6
Inter7 Courier-IMAP 1.7
Inter7 Courier-IMAP 2.0 .0
Inter7 Courier-IMAP 2.1
Inter7 Courier-IMAP 2.1.1
Inter7 Courier-IMAP 2.1.2
Inter7 Courier-IMAP 2.2 .0
Inter7 Courier-IMAP 2.2.1
Double Precision Incorporated SqWebMail 3.5.2
Double Precision Incorporated SqWebMail 3.5.3
Double Precision Incorporated SqWebMail 3.6 .0
Double Precision Incorporated SqWebMail 3.6.1
Double Precision Incorporated SqWebMail 3.6.2
Solution:
The vendor has released Courier MTA 0.45, Courier-IMAP 3.0.0, and SqWebMail 4.0.0 to address these issues.
Gentoo have released an advisory (GLSA 200403-06) and updates to address this issue. Gentoo users are advised to upgrade to current packages by emerging the updated packages as follows:
# emerge sync
And depending on your installation:
# emerge -pv ">=net-mail/courier-imap-3.0.0"
# emerge ">=net-mail/courier-imap-3.0.0"
Or:
# emerge -pv ">=net-mail/courier-0.45"
# emerge ">=net-mail/courier-0.45"
Double Precision Incorporated Courier MTA 0.37.3
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.38.1
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.40
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.40.1
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.42.2
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.43
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.43.1
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.43.2
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.44
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated Courier MTA 0.44.2
-
Double Precision Incorporated courier-0.45.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 1.6
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 1.7
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 2.0 .0
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 2.1
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 2.1.1
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 2.1.2
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 2.2 .0
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Inter7 Courier-IMAP 2.2.1
-
Inter7 courier-imap-3.0.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated SqWebMail 3.5.2
-
Double Precision Incorporated sqwebmail-4.0.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated SqWebMail 3.5.3
-
Double Precision Incorporated sqwebmail-4.0.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated SqWebMail 3.6 .0
-
Double Precision Incorporated sqwebmail-4.0.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated SqWebMail 3.6.1
-
Double Precision Incorporated sqwebmail-4.0.1.tar.bz2
http://www.courier-mta.org/download.php
Double Precision Incorporated SqWebMail 3.6.2
-
Double Precision Incorporated sqwebmail-4.0.1.tar.bz2
http://www.courier-mta.org/download.php
References
Courier Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- Courier Mail Server: Release Notes (Courier)
- Vendor Homepage (Courier)