int(3564)

Vulnerability Bulletins


Ejecución de código arbitrario en Perdition Mail Retrieval Proxy

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Perdition Mail Retrieval Proxy <= 1.17

Description

Se ha encontrado una vulnerabilidad en Perdition Mail Retrieval Proxy en las versiones 1.17 y anteriores. La vulnerabilidad reside en un error en el mecanismo de protección del formato de string en IMAPD.

Un atacante remoto podría ejecutar código arbitrario mediante una etiqueta IMAP con un byte nulo seguido de un formato de string específico que no se tiene en cuenta en dicho mecanismo de protección.

Solution



Actualización de software

Debian (DSA 1398-1)
Source
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1.diff.gz
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15.orig.tar.gz
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1.dsc
alpha
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_alpha.deb
arm
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_arm.deb
i386
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_i386.deb
ia64
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_ia64.deb
m68k
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_m68k.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_m68k.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_m68k.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_m68k.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_m68k.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_m68k.deb
mips
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_mips.deb
mipsel
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_mipsel.deb
powerpc
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_powerpc.deb
s390
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_s390.deb
sparc
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.15-5sarge1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.15-5sarge1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.15-5sarge1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.15-5sarge1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.15-5sarge1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.15-5sarge1_sparc.deb
Source
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17.orig.tar.gz
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1.dsc
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1.diff.gz
alpha
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_alpha.deb
amd64
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_amd64.deb
arm
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_arm.deb
i386
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_i386.deb
ia64
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_ia64.deb
mips
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_mips.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_mips.deb
mipsel
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_mipsel.deb
powerpc
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_powerpc.deb
s390
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_s390.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_s390.deb
sparc
http://security.debian.org/pool/updates/main/p/perdition/perdition-postgresql_1.17-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-dev_1.17-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-ldap_1.17-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-odbc_1.17-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition_1.17-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perdition/perdition-mysql_1.17-7etch1_sparc.deb

Standar resources

Property Value
CVE CVE-2007-5740
BID

Other resources

Debian Security Advisory (DSA 1398-1)
http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00176.html

Version history

Version Comments Date
1.0 Aviso emitido 2007-11-08
Ministerio de Defensa
CNI
CCN
CCN-CERT