xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Mutt IMAP远程文件夹缓冲区溢出漏洞


发布时间:2003-03-28
更新时间:2003-04-07
严重程度:
威胁程度:普通用户访问权限
错误类型:边界检查错误
利用方式:服务器模式

BUGTRAQ ID:7229
CVE(CAN) ID:CAN-2003-0167

受影响系统
Mutt Mutt 1.2.5
   +Caldera OpenLinux 2.3
   +Caldera OpenLinux 3.1 -IA64
   +Caldera OpenLinux eBuilder 3.0
   +Caldera OpenLinux Server 3.1
   +Caldera OpenLinux Server 3.1.1
   +Caldera OpenLinux Workstation 3.1
   +Caldera OpenLinux Workstation 3.1.1
   +Conectiva Linux 6.0
   +Debian Linux 2.2 68k
   +Debian Linux 2.2 alpha
   +Debian Linux 2.2 arm
   +Debian Linux 2.2 IA-32
   +Debian Linux 2.2 powerpc
   +Debian Linux 2.2 sparc
   +HP Secure OS software for Linux 1.0
   +RedHat Linux 7.0 alpha
   +RedHat Linux 7.0 i386
   +RedHat Linux 7.0 sparc
   +RedHat Linux 7.0 J i386
   +RedHat Linux 7.1 alpha
   +RedHat Linux 7.1 i386
   +RedHat Linux 7.1 ia64
   +RedHat Linux 7.2 i386
   +RedHat Linux 7.2 ia64
   +SCO eDesktop 2.4
   +SCO eServer 2.3.1
   +Trustix Secure Linux 1.2
   +Trustix Secure Linux 1.5
Mutt Mutt 1.3.12 -1
Mutt Mutt 1.3.12
   +S.u.S.E. Linux 7.1 alpha
   +S.u.S.E. Linux 7.1 ppc
   +S.u.S.E. Linux 7.1 sparc
   +S.u.S.E. Linux 7.1 x86
Mutt Mutt 1.3.16
   +S.u.S.E. Linux 7.2
   +S.u.S.E. Linux 7.2 i386
Mutt Mutt 1.3.17
   +Conectiva Linux 7.0
Mutt Mutt 1.3.22
   +S.u.S.E. Linux 7.3
   +S.u.S.E. Linux 7.3 i386
   +S.u.S.E. Linux 7.3 ppc
   +S.u.S.E. Linux 7.3 sparc
Mutt Mutt 1.3.24
Mutt Mutt 1.3.25
Mutt Mutt 1.3.27
   +S.u.S.E. Linux 8.0
   +S.u.S.E. Linux 8.0 i386
Mutt Mutt 1.3.28
   +Debian Linux 3.0
   +Debian Linux 3.0 alpha
   +Debian Linux 3.0 arm
   +Debian Linux 3.0 hppa
   +Debian Linux 3.0 ia-32
   +Debian Linux 3.0 ia-64
   +Debian Linux 3.0 m68k
   +Debian Linux 3.0 mips
   +Debian Linux 3.0 mipsel
   +Debian Linux 3.0 ppc
   +Debian Linux 3.0 s/390
   +Debian Linux 3.0 sparc
   +MandrakeSoft Linux Mandrake 8.2
   +MandrakeSoft Linux Mandrake 8.2 ppc
详细描述
Mutt存在一个缓冲区溢出漏洞。

Mutt提供一个功能,允许远程用户通过IMAP文件夹读取邮件。IMAP服务器上特殊构建的文件夹可能触发缓冲区溢出导致Mutt客户端崩溃,精心构建的文件夹数据可能以用户进程权限在系统上执行任意指令。

目前还没有该漏洞的详细信息。

解决方案
Mutt Mutt 1.2.5:
     Debian Upgrade mutt_1.2.5-5.2_alpha.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_alpha.deb
     Debian Upgrade mutt_1.2.5-5.2_arm.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_arm.deb
     Debian Upgrade mutt_1.2.5-5.2_i386.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_i386.deb
     Debian Upgrade mutt_1.2.5-5.2_m68k.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_m68k.deb
     Debian Upgrade mutt_1.2.5-5.2_powerpc.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_powerpc.deb
     Debian Upgrade mutt_1.2.5-5.2_sparc.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_sparc.deb
Mutt Mutt 1.3.12 -1:
Mutt Mutt 1.3.12:
Mutt Mutt 1.3.16:
Mutt Mutt 1.3.17:
Mutt Mutt 1.3.22:
Mutt Mutt 1.3.24:
Mutt Mutt 1.3.25:
Mutt Mutt 1.3.27:
Mutt Mutt 1.3.28:
     Debian Upgrade mutt-utf8_1.3.28-2.2_sparc.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_sparc.deb
     Debian Upgrade mutt_1.3.28-2.2_sparc.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_sparc.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_s390.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_s390.deb
     Debian Upgrade mutt_1.3.28-2.2_s390.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_s390.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_powerpc.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_powerpc.deb
     Debian Upgrade mutt_1.3.28-2.2_powerpc.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_powerpc.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_mipsel.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_mipsel.deb
     Debian Upgrade mutt_1.3.28-2.2_mipsel.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_mipsel.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_mips.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_mips.deb
     Debian Upgrade mutt_1.3.28-2.2_mips.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_mips.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_m68k.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_m68k.deb
     Debian Upgrade mutt_1.3.28-2.2_m68k.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_m68k.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_hppa.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_hppa.deb
     Debian Upgrade mutt_1.3.28-2.2_hppa.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_hppa.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_ia64.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_ia64.deb
     Debian Upgrade mutt_1.3.28-2.2_ia64.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_ia64.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_i386.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_i386.deb
     Debian Upgrade mutt_1.3.28-2.2_i386.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_i386.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_arm.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_arm.deb
     Debian Upgrade mutt_1.3.28-2.2_arm.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_arm.deb
     Debian Upgrade mutt-utf8_1.3.28-2.2_alpha.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_alpha.deb
     Debian Upgrade mutt_1.3.28-2.2_alpha.deb
     http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_alpha.deb

相关信息
报告:Byrial Jensen
相关资料:http://online.securityfocus.com/advisories/5189
          http://online.securityfocus.com/advisories/5238