Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier
Date: Mon, 29 Mar 2004 08:16:29
Message-Id: 20040329081417.GB24315@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200403-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Multiple remote buffer overflow vulnerabilities in Courier
9 Date: March 26, 2004
10 Bugs: #45584
11 ID: 200403-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Remote buffer overflow vulnerabilites have been found in Courier-IMAP
19 and Courier MTA. These exploits may allow the execution of abritrary
20 code, allowing unauthorized access to a vulnerable system.
21
22 Background
23 ==========
24
25 Courier MTA is a multiprotocol mail server suite that provides webmail,
26 mailing lists, IMAP, and POP3 services. Courier-IMAP is a standalone
27 server that gives IMAP access to local mailboxes.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 net-mail/courier-imap < 3.0.0 >= 3.0.0
36 net-mail/courier < 0.45 >= 0.45
37
38 Description
39 ===========
40
41 The vulnerabilities have been found in the 'SHIFT_JIS' converter in
42 'shiftjis.c' and 'ISO2022JP' converter in 'so2022jp.c'. An attacker may
43 supply Unicode characters that exceed BMP (Basic Multilingual Plane)
44 range, causing an overflow.
45
46 Impact
47 ======
48
49 An attacker without privileges may exploit this vulnerability remotely,
50 allowing arbitrary code to be executed in order to gain unauthorized
51 access.
52
53 Workaround
54 ==========
55
56 While a workaround is not currently known for this issue, all users are
57 advised to upgrade to the latest version of the affected packages.
58
59 Resolution
60 ==========
61
62 All users should upgrade to the current version of the affected
63 packages:
64
65 # emerge sync
66
67 # emerge -pv ">=net-mail/courier-imap-3.0.0"
68 # emerge ">=net-mail/courier-imap-3.0.0"
69
70 # ** Or; depending on your installation... **
71
72 # emerge -pv ">=net-mail/courier-0.45"
73 # emerge ">=net-mail/courier-0.45"
74
75 References
76 ==========
77
78 [ 1 ] http://www.securityfocus.com/bid/9845
79 [ 2 ] http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0224
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 http://bugs.gentoo.org.