what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

fetchmail.6.1.3.txt

fetchmail.6.1.3.txt
Posted Dec 14, 2002
Authored by Stefan Esser | Site security.e-matters.de

A heap overflow has been found in Fetchmail v6.1.3 and below which allows remote attackers to execute code with the privileges of the user running fetchmail on Linux. It is a denial of service vulnerability on BSD. Fixed in v6.2.0.

tags | advisory, remote, denial of service, overflow
systems | linux, bsd
SHA-256 | 00367f13a6c9121041c44e2a0b3582239a66f54aeae1714fc5cf1dc427242f38

fetchmail.6.1.3.txt

Change Mirror Download
                           e-matters GmbH
www.e-matters.de

-= Security Advisory =-



Advisory: Fetchmail remote vulnerability
Release Date: 2002/12/13
Last Modified: 2002/12/13
Author: Stefan Esser [s.esser@e-matters.de]

Application: Fetchmail <= 6.1.3
Severity: A vulnerability within Fetchmail could allow
remote compromise.
Risk: Critical
Vendor Status: Vendor released version 6.2.0
Reference: http://security.e-matters.de/advisories/052002.html


Overview:

In the light of recent discoveries we reaudited Fetchmail and found
another bufferoverflow within the default configuration. This heap
overflow can be used by remote attackers to crash it or to execute
arbitrary code with the privileges of the user running fetchmail.
Depending on the configuration this allows a remote root compromise.


Details:

When Fetchmail retrieves a mail it performs the so called reply-hack.
This basicly means that all headers that contain addresses are searched
for local addresses (without @domain part). When such an address is
found, Fetchmail appends an @ and the hostname of the mailserver to it.
To avoid unnecessary reallocating of the output buffer during this
process Fetchmail counts the number of addresses within the headerline
first. Then it reserves enough space for the case that all addresses
are locals. Unfourtunately this calculation is wrong because it counts
a) to many addresses and b) only takes the hostname in count and not
the extra @ which is also appended. This means at the moment where you
have enough (due to a) local addresses within the headerline every
additional address will overflow the buffer by one byte. This results
in an arbitrary size heap overflow, which was proved to be exploitable
on our Linux boxes. Due to the fact that this heapoverflow occurs in
malloc()ed areas we believe that BSD systems can only be crashed with
this bug.

Finally it is important to mention that an attacker does not need
to spoof dns records, or control the mailserver to exploit this bug.
It is usually enough to send a mail to the victim that contains
specially crafted header lines.


Proof of Concept:

e-matters is not going to release an exploit for this vulnerability to
the public.


Vendor Response:

08. December 2002 - A patch that fixes this vulnerability was mailed
to the vendor.

13. December 2002 - Vendor released Fetchmail v6.2.0 which fixes
this vulnerability.


Recommendation:

If you are running Fetchmail we suggest to upgrade to a new or patched
version as soon as possible.


GPG-Key:

http://security.e-matters.de/gpg_key.asc

pub 1024D/75E7AAD6 2002-02-26 e-matters GmbH - Securityteam
Key fingerprint = 43DD 843C FAB9 832A E5AB CAEB 81F2 8110 75E7 AAD6


Copyright 2002 Stefan Esser. All rights reserved.



Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    54 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    18 Files
  • 14
    May 14th
    11 Files
  • 15
    May 15th
    17 Files
  • 16
    May 16th
    13 Files
  • 17
    May 17th
    22 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    17 Files
  • 21
    May 21st
    18 Files
  • 22
    May 22nd
    7 Files
  • 23
    May 23rd
    111 Files
  • 24
    May 24th
    27 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    6 Files
  • 28
    May 28th
    12 Files
  • 29
    May 29th
    31 Files
  • 30
    May 30th
    22 Files
  • 31
    May 31st
    18 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close