Vulnerability Note VU#5648
Buffer Overflows in various email clients
Overview
Buffer Overflows in several MIME headers affect a large number of electronic mail clients.
Description
A variety of electronic mail clients (circa 1998) are vulnerable to buffer overflow attacks in the code that processes MIME headers. See the vendor statements referenced below for details specific to each mail client. |
Impact
An intruder can crash vulnerable mail clients, or use them to execute arbitrary code with the privileges of the user reading the mail. |
Solution
Fixing the problem requires modifying each email client with an appropriate patch from the vendor. |
There are several things that can be done to mitigate the risk if a patch cannot be installed. |
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Data General | Unknown | - | 20 Apr 2002 |
| Eric Allman | Not Vulnerable | - | 20 Apr 2002 |
| Fujitsu | Not Vulnerable | - | 20 Apr 2002 |
| Hewlett-Packard Company | Vulnerable | - | 11 Apr 2003 |
| Lotus Software | Unknown | 07 Aug 1998 | 11 Apr 2003 |
| Microsoft Corporation | Vulnerable | - | 11 Apr 2003 |
| Mutt | Vulnerable | - | 20 Apr 2002 |
| NCR | Not Vulnerable | - | 20 Apr 2002 |
| NetBSD | Vulnerable | - | 20 Apr 2002 |
| OpenBSD | Not Vulnerable | - | 20 Apr 2002 |
| Pegasus Mail | Not Vulnerable | - | 20 Apr 2002 |
| QUALCOMM | Not Vulnerable | - | 20 Apr 2002 |
| Sun Microsystems Inc. | Vulnerable | - | 11 Apr 2003 |
| The SCO Group (SCO Linux) | Vulnerable | - | 11 Apr 2003 |
| The SCO Group (SCO UnixWare) | Unknown | - | 11 Apr 2003 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.microsoft.com/security/bulletins/ms98-008.htm
- http://www.netscape.com/products/security/resources/bugs/longfile.html
- http://www.ciac.org/ciac/MIMEfaq.html
- http://www.ciac.org/ciac/bulletins/i-077a.shtml
- ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-98.02.Outlook.buffer.overflow
- http://www.sjmercury.com/business/tech/docs/security072898.htm
Credit
This document was written by Shawn V Hernan.
Other Information
- CVE IDs: Unknown
- CERT Advisory: CA-1998-10
- Date Public: 27 Jul 98
- Date First Published: 20 Sep 2001
- Date Last Updated: 11 Apr 2003
- Severity Metric: 81.00
- Document Revision: 6
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify