漏洞信息详情
Mutt UTF-7 Internationalized远程文件夹缓冲区溢出漏洞
- CNNVD编号:CNNVD-200303-068
- 危害等级: 高危
- CVE编号:
CVE-2003-0140
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-03-24
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
mutt - 漏洞来源:
Discovered by Dieg… -
漏洞简介
Mutt 1.4.0可能还包括更早版本,1.5.x到1.5.3版本以及其他使用Mutt代码如Balsa 2.0.10之前版本的程序存在缓冲区溢出漏洞。远程恶意IMAP服务器可以借助一个畸形文件夹导致服务拒绝(崩溃),并且可能还可以执行任意代码。
漏洞公告
Conectiva has released an additional advisory CLA-2003:635 that contains fixes to address this issue in Balsa.
Users are advised to upgrade to version 1.4.1 (stable). The patched unstable version is 1.5.4.
OpenPKG has made fixed versions available, and released advisory OpenPKG-SA-2003.025 to address this issue.
Slackware has released fixes for this issue. Users are advised to upgrade to mutt-1.4.1i.
Gentoo Linux has addressed this issue in advisory 200303-19. Affected users have been advised to issue the following commands to upgrade the vulnerable package:
emerge sync
emerge mutt
emerge clean
Red Hat Linux has released an advisory (RHSA-2003:109-03). Information about obtaining and applying fixes are available in the referenced advisory.
Conectiva has released advisory CLA-2003:626 to address this issue. An additional advisory has been released (CLA-2003:630) which contains fixes which address this issue in Balsa.
Gentoo Linux has released a new advisory. Users who have installed net-mail/balsa are advised to upgrade to balsa-2.0.10 by issuing the following commands:
emerge sync
emerge balsa
emerge clean
Red Hat has also released an advisory (RHSA-2003:111-08) which contains upgrade details for Enterprise distributions, which are available through the Red Hat Network.
GNOME Balsa 1.2.4
-
Conectiva balsa-1.2.4-2U80_1cl.i386.rpmConectiva 8
ftp://atualizacoes.conectiva.com.br/8/RPMS/balsa-1.2.4-2U80_1cl.i386.r
pm -
Conectiva balsa-help-1.2.4-2U80_1cl.i386.rpmConectiva 8
ftp://atualizacoes.conectiva.com.br/8/RPMS/balsa-help-1.2.4-2U80_1cl.i
386.rpm -
Conectiva balsa-2.0.9-29086U90_1cl.i386.rpmConectiva 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/balsa-2.0.9-29086U90_1cl.i3
86.rpm -
Conectiva balsa-help-2.0.9-29086U90_1cl.i386.rpmConectiva 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/balsa-help-2.0.9-29086U90_1
cl.i386.rpm -
Sun balsa-1.2.4-7.7.2.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM
S/balsa-1.2.4-7.7.2.i386.rpm
Mutt Mutt 1.3.12
-
Mutt mutt-1.4.1i.tar.gz
ftp://ftp.mutt.org/mutt/mutt-1.4.1i.tar.gz -
SuSE mutt-1.3.12i-15.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/mutt-1.3.12i-15.alpha.rp
m -
SuSE mutt-1.3.12i-16.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/mutt-1.3.12i-16.ppc.rpm -
SuSE mutt-1.3.12i-69.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/mutt-1.3.12i-69.i386.rp
m
Mutt Mutt 1.3.16
-
Mutt mutt-1.4.1i.tar.gz
ftp://ftp.mutt.org/mutt/mutt-1.4.1i.tar.gz -
SuSE mutt-1.3.16i-92.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/mutt-1.3.16i-92.i386.rp
m
Mutt Mutt 1.3.17
-
Conectiva mutt-1.3.17-8U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mutt-1.3.17-8U70_2cl.i386
.rpm -
Mutt mutt-1.4.1i.tar.gz
ftp://ftp.mutt.org/mutt/mutt-1.4.1i.tar.gz
Mutt Mutt 1.3.22
-
Mutt mutt-1.4.1i.tar.gz
ftp://ftp.mutt.org/mutt/mutt-1.4.1i.tar.gz -
SuSE mutt-1.3.22.1i-124.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n1/mutt-1.3.22.1i-124.ppc.r
pm -
SuSE mutt-1.3.22.1i-170.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n1/mutt-1.3.22.1i-170.i386
.rpm -
SuSE mutt-1.3.22.1i-39.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n1/mutt-1.3.22.1i-39.spar
c.rpm
Mutt Mutt 1.3.24
-
Mutt mutt-1.4.1i.tar.gz
ftp://ftp.mutt.org/mutt/mutt-1.4.1i.tar.gz
Mutt Mutt 1.3.25
-
Conectiva mutt-1.3.25-2U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/mutt-1.3.25-2U80_1cl.i386.r
pm -
Mutt mutt-1.4.1i.tar.gz
ftp://ftp.mutt.org/mutt/mutt-1.4.1i.tar.gz
Mutt Mutt 1.3.27
-
SuSE mutt-1.3.27i-77.i386.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/mutt-1.3.27i-77.i386.pa
tch.rpm -
SuSE mutt-1.3.27i-77.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/mutt-1.3.27i-77.i386.rp
m
Mutt Mutt 1.3.28
-
Debian mutt-utf8_1.3.28-2.1_alpha.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2
.1_alpha.deb -
Debian mutt-utf8_1.3.28-2.1_arm.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2
.1_arm.deb -
Debian mutt-utf8_1.3.28-2.1_hppa.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2
.1_hppa.deb -
Debian mutt-utf8_1.3.28-2.1_i386.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2
.1_i386.deb -
Debian mutt-utf8_1.3.28-2.1_ia64.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2
.1_ia64.deb -
Debian mutt-utf8_1.3.28-2.1_m68k.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2
.1_m68k.deb -
Debian mutt-utf8_1.3.28-2.1_mips.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2
.1_mips.deb - Debian mutt-utf8_1.3.28-2.1_mips
参考网址
来源: BID
名称: 7120
链接:http://www.securityfocus.com/bid/7120
来源: BUGTRAQ
名称: 20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104818814931378&w=2
来源: XF
名称: mutt-folder-name-bo(11583)
链接:http://xforce.iss.net/xforce/xfdb/11583
来源: BUGTRAQ
名称: 20030319 mutt-1.4.1 fixes a buffer overflow.
链接:http://www.securityfocus.com/archive/1/315679
来源: REDHAT
名称: RHSA-2003:109
链接:http://www.redhat.com/support/errata/RHSA-2003-109.html
来源: SUSE
名称: SuSE-SA:2003:020
链接:http://www.novell.com/linux/security/advisories/2003_020_mutt.html
来源: DEBIAN
名称: DSA-268
链接:http://www.debian.org/security/2003/dsa-268
来源: MANDRAKE
名称: MDKSA-2003:041
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:041
来源: GENTOO
名称: GLSA-200303-19
链接:http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml
来源: www.coresecurity.com
链接:http://www.coresecurity.com/common/showdoc.php?idx=310&idxseccion=10
来源: BUGTRAQ
名称: 20030430 GLSA: balsa (200304-10)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105171507629573&w=2
来源: BUGTRAQ
名称: 20030322 GLSA: mutt (200303-19)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104852190605988&w=2
来源: BUGTRAQ
名称: 20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104817995421439&w=2
来源: CONECTIVA
名称: CLA-2003:630
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000630
来源: CONECTIVA
名称: CLA-2003:626
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000626
来源: US Government Resource: oval:org.mitre.oval:def:434
名称: oval:org.mitre.oval:def:434
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:434
来源: US Government Resource: oval:org.mitre.oval:def:2
名称: oval:org.mitre.oval:def:2
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2