漏洞信息详情
Mutt处理地址缓冲区溢出漏洞
- CNNVD编号:CNNVD-200202-015
- 危害等级: 高危
- CVE编号:
CVE-2002-0001
- 漏洞类型:
边界条件错误
- 发布时间:
2002-02-27
- 威胁类型:
远程
- 更新时间:
2006-09-21
- 厂 商:
mutt - 漏洞来源:
Discovered by Joos… -
漏洞简介
mutt 1.2.5.1之前版本和mutt 1.3.25之前1.3.x版本中的RFC822地址解析器存在漏洞。远程攻击者可以借助不正确终止的评论或者地址列表中的解析器执行任意命令。
漏洞公告
Users of HP Secure OS software for Linux Release 1.0 have been advised to download the appropriate patch given for Red Hat Linux 7.1. For details, refer to advisory HPSBTL0201-011, listed in the references section.
Updated versions are available:
Mutt Mutt 0.93.2
-
Mutt mutt-1.2.5.1.tar.gz
ftp://ftp.mutt.org/pub/mutt/mutt-1.2.5.1.tar.gz
Mutt Mutt 1.0.1
-
Conectiva ecommerce mutt-1.2.5-7U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/mutt-1.
2.5-7U50_1cl.i386.rpm -
Conectiva graficas mutt-1.2.5-7U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/mutt-1.2
.5-7U50_1cl.i386.rpm -
Conectiva mutt-1.2.5-7U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/mutt-1.2.5-7U50_1cl.i386.
rpm -
Conectiva mutt-1.2.5-7U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/mutt-1.2.5-7U51_1cl.i386.
rpm -
Mutt mutt-1.2.5.1.tar.gz
ftp://ftp.mutt.org/pub/mutt/mutt-1.2.5.1.tar.gz -
Red Hat 6.2 alpha mutt-1.2.5.1-0.6.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/mutt-1.2.5.1-0.6.alpha.rpm -
Red Hat 6.2 i386 mutt-1.2.5.1-0.6.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/mutt-1.2.5.1-0.6.i386.rpm -
Red Hat 6.2 sparc mutt-1.2.5.1-0.6.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/mutt-1.2.5.1-0.6.sparc.rpm -
S.u.S.E. mutt-1.0.1i-30.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/6.4/n1/mutt-1.0.1i-30.i386.rpm
-
S.u.S.E. mutt-1.0.1i-30.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/6.4/n1/mutt-1.0.1i-30.ppc.rpm
Mutt Mutt 1.2.5
-
Caldera mutt-1.2.5-12.i386
ftp://ftp.caldera.com/pub/updates/eDesktop/2.4/current/RPMS/mutt-1.2.5
-12.i386.rpm -
Caldera mutt-1.2.5-12.i386
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS/mutt-1.2.5-
12.i386.rpm -
Caldera mutt-1.2.5-12.i386
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/
mutt-1.2.5-12.i386.rpm -
Caldera mutt-1.2.5-12.i386
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/mu
tt-1.2.5-12.i386.rpm -
Caldera mutt-1.2.5-12.i386
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RP
MS/mutt-1.2.5-12.i386.rpm -
Caldera mutt-1.2.5-12.i386
tp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/R
PMS/mutt-1.2.5-12.i386.rpm -
Caldera mutt-1.2.5-12.ia64
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/IA64/current/RPMS/mutt
-1.2.5-12.ia64.rpm -
Caldera mutt-1.2.5-12OL.i386
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS/mutt-1.2.
5-12OL.i386.rpm -
Conectiva mutt-1.2.5-7U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/mutt-1.2.5-7U60_1cl.i386.
rpm -
Debian mutt_1.2.5-5_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/mutt
_1.2.5-5_alpha.deb -
Debian mutt_1.2.5-5_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/mutt_1
.2.5-5_arm.deb -
Debian mutt_1.2.5-5_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/mutt_
1.2.5-5_i386.deb -
Debian mutt_1.2.5-5_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/mutt_
1.2.5-5_m68k.deb -
Debian mutt_1.2.5-5_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/mu
tt_1.2.5-5_powerpc.deb -
Debian mutt_1.2.5-5_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/mutt
_1.2.5-5_sparc.deb -
FreeBSD ports-4 i386 mutt-1.2.5_1.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/mail/mu
tt-1.2.5_1.tgz -
FreeBSD ports-5 i386 mutt-1.2.5_1.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/mail/m
utt-1.2.5_1.tgz -
Mutt mutt-1.2.5.1.tar.gz
ftp://ftp.mutt.org/pub/mutt/mutt-1.2.5.1.tar.gz -
Red Hat 7.0 alpha mutt-1.2.5.1-0.7.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/mutt-1.2.5.1-0.7.alpha.rpm -
Red Hat 7.0 i386 mutt-1.2.5.1-0.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/mutt-1.2.5.1-0.7.i386.rpm -
Red Hat 7.0J i386 mutt-1.2.5.1-0.7j.i386.rpm
ftp://updates.redhat.com/7.0/ja/os/i386/mutt-1.2.5.1-0.7j.i386.rpm -
Red Hat 7.1 alpha mutt-1.2.5.1-0.7.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/mutt-1.2.5.1-0.7.alpha.rpm -
Red Hat 7.1 i386 mutt-1.2.5.1-0.7.i386.rpm
参考网址
来源: REDHAT
名称: RHSA-2002:003
链接:http://www.redhat.com/support/errata/RHSA-2002-003.html来源: DEBIAN
名称: DSA-096
链接:http://www.debian.org/security/2002/dsa-096来源: BUGTRAQ
名称: 20020101 [Announce] SECURITY: mutt-1.2.5.1 and mutt-1.3.25 released.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=100994648918287&w=2来源: BID
名称: 3774
链接:http://www.securityfocus.com/bid/3774来源: SUSE
名称: SuSE-SA:2002:001
链接:http://www.novell.com/linux/security/advisories/2002_001_mutt_txt.html来源: www.mutt.org
链接:http://www.mutt.org/announce/mutt-1.2.5.1-1.3.25.html来源: XF
名称: mutt-address-handling-bo(7759)
链接:http://www.iss.net/security_center/static/7759.php来源: HP
名称: HPSBTL0201-011
链接:http://online.securityfocus.com/advisories/3778来源: CONECTIVA
名称: CLA-2002:449
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000449来源: FREEBSD
名称: FreeBSD-SA-02:04
链接:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:04.mutt.asc来源: CALDERA
名称: CSSA-2002-002.0
链接:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-002.0.txt