Eric S. Raymond Fetchmail Email头信息解析存在缓冲溢出漏洞发布时间:2002-10-08 更新时间:2002-10-08 严重程度:中 威胁程度:远程拒绝服务 错误类型:边界检查错误 利用方式:客户机模式 BUGTRAQ ID:5825 受影响系统 Eric Raymond Fetchmail 5.4详细描述 Fetchmail存在缓冲溢出,漏洞是由于对用户提供的EMAIL头值缺少正确检查。 当拷贝信息到堆栈缓冲区的时候,Fetchmail没有正确检查某些用户指定数据的大小,远程攻击者可以发送恶意邮件导致Fetchmail不正确的在堆栈上分配空间大小,导致缓冲溢出,存在执行任意代码可能。 测试代码 无 解决方案 升级程序: Eric Raymond Fetchmail 5.4: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz EnGarde Secure Linux RPM fetchmail-ssl-6.1.0-1.0.5.i386.rpm ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i386/fetchmail-ssl-6.1.0-1.0.5.i386.rpm EnGarde Secure Linux RPM fetchmail-ssl-6.1.0-1.0.5.i686.rpm ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i686/fetchmail-ssl-6.1.0-1.0.5.i686.rpm Eric Raymond Fetchmail 5.5: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.6: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.7: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.8: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.9.6: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.9.7: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.9.8: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.9.9: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.9.10: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.9.11: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz Eric Raymond Fetchmail 5.9.12: Eric Raymond Fetchmail 5.9.13: Eric Raymond Fetchmail 5.9.14: Eric Raymond Fetchmail 6.0 .0: Eric Raymond Upgrade fetchmail-6.1.0.tar.gz http://www.tuxedo.org/~esr/fetchmail/fetchmail-6.1.0.tar.gz 相关信息 Stefan Esser <s.esser@e-matters.de>. 参考:http://online.securityfocus.com/advisories/4509 http://online.securityfocus.com/advisories/4520 http://online.securityfocus.com/archive/1/293541 相关主页:http://www.tuxedo.org/~esr/fetchmail/ |