int(1166)

Boletines de Vulnerabilidades


Múltiples vulnerabilidades en Cyrus IMAP Server

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Obtener acceso
Dificultad Avanzado
Requerimientos del atacante Acceso remoto sin cuenta a un servicio estandar

Información sobre el sistema

Propiedad Valor
Fabricante afectado GNU/Linux
Software afectado Cyrus IMAP Server <= 2.2.8

Descripción

Se han encontrado varias vulnerabilidades relacionadas con el demonio Cyrus IMAP. Debido a una vulnerabilidad en el comando de parseo es posible acceder a memoria más allá del espacio que le corresponde al búfer, lo que podría habilitar una ejecución de código remota.

Solución



Actualización de software

Debian

Debian Linux 3.0
Source:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2.dsc
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2.diff.gz
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19.orig.tar.gz
Arquitectura Alpha:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_alpha.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_alpha.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_alpha.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_alpha.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_alpha.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_alpha.deb
Arquitectura ARM:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_arm.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_arm.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_arm.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_arm.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_arm.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_arm.deb
Arquitectura Intel IA-32:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_i386.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_i386.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_i386.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_i386.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_i386.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_i386.deb
Arquitectura Intel IA-64:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_ia64.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_ia64.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_ia64.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_ia64.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_ia64.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_ia64.deb
Arquitectura HP Precision:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_hppa.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_hppa.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_hppa.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_hppa.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_hppa.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_hppa.deb
Arquitectura Motorola 680x0:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_m68k.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_m68k.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_m68k.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_m68k.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_m68k.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_m68k.deb
Arquitectura Big endian MIPS:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_mips.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_mips.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_mips.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_mips.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_mips.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_mips.deb
Arquitectura Little endian MIPS:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_mipsel.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_mipsel.deb
Arquitectura PowerPC:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_powerpc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_powerpc.deb
Arquitectura IBM S/390:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_s390.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_s390.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_s390.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_s390.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_s390.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_s390.deb
Arquitectura Sun Sparc:
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-admin_1.5.19-9.2_sparc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-common_1.5.19-9.2_sparc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-dev_1.5.19-9.2_sparc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-imapd_1.5.19-9.2_sparc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-nntp_1.5.19-9.2_sparc.deb
http://security.debian.org/pool/updates/main/c/cyrus-imapd/cyrus-pop3d_1.5.19-9.2_sparc.deb

Mandrake Linux
Mandrakelinux 10.0
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/cyrus-imapd-2.1.16-5.3.100mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/cyrus-imapd-devel-2.1.16-5.3.100mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/cyrus-imapd-murder-2.1.16-5.3.100mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/cyrus-imapd-utils-2.1.16-5.3.100mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/perl-Cyrus-2.1.16-5.3.100mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/SRPMS/cyrus-imapd-2.1.16-5.3.100mdk.src.rpm
Mandrakelinux 10.0/AMD64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/cyrus-imapd-2.1.16-5.3.100mdk.amd64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/cyrus-imapd-devel-2.1.16-5.3.100mdk.amd64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/cyrus-imapd-murder-2.1.16-5.3.100mdk.amd64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/cyrus-imapd-utils-2.1.16-5.3.100mdk.amd64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/perl-Cyrus-2.1.16-5.3.100mdk.amd64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/SRPMS/cyrus-imapd-2.1.16-5.3.100mdk.src.rpm
Mandrakelinux 10.1
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/cyrus-imapd-2.2.8-4.1.101mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/cyrus-imapd-devel-2.2.8-4.1.101mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/cyrus-imapd-murder-2.2.8-4.1.101mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/cyrus-imapd-nntp-2.2.8-4.1.101mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/cyrus-imapd-utils-2.2.8-4.1.101mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/perl-Cyrus-2.2.8-4.1.101mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/SRPMS/cyrus-imapd-2.2.8-4.1.101mdk.src.rpm
Mandrakelinux 10.1/X86_64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/cyrus-imapd-2.2.8-4.1.101mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/cyrus-imapd-devel-2.2.8-4.1.101mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/cyrus-imapd-murder-2.2.8-4.1.101mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/cyrus-imapd-nntp-2.2.8-4.1.101mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/cyrus-imapd-utils-2.2.8-4.1.101mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/perl-Cyrus-2.2.8-4.1.101mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/SRPMS/cyrus-imapd-2.2.8-4.1.101mdk.src.rpm


SUSE Linux
cyrus-imapd
Descargue los parches necesarios mediante YAST o desde el servidor FTP oficial de SUSE

Apple
Mac OS X Server v10.3.8
http://www.apple.com/support/downloads/securityupdate2005003server.html

Identificadores estándar

Propiedad Valor
CVE CAN-2004-1011
CAN-2004-1012
CAN-2004-1013
BID

Recursos adicionales

Debian Security Advisory DSA 597-1
http://lists.debian.org/debian-security-announce/debian-security-announce-2004/msg00207.html

Mandrakesoft Security Advisories (MDKSA-2004:139)
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:139

SUSE Security Summary Report SUSE-SR:2004:003
http://www.suse.de/de/security/2004_03_sr.html

Apple Security Update 2005-003
http://docs.info.apple.com/article.html?artnum=301061

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2004-11-24
1.1 Aviso emitido por Mandrake Linux (MDKSA-2004:139) 2004-11-26
1.2 Aviso emitido por SUSE Linux (SUSE-SR:2004:003) 2004-12-10
1.3 Aviso emitido por Apple (2005-003) 2005-03-22

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT