Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 175023 - mail-client/mutt APOP design error (CVE-2007-1558)
Summary: mail-client/mutt APOP design error (CVE-2007-1558)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: B3 [noglsa] jaervosz
Keywords:
Depends on: 178003
Blocks:
  Show dependency tree
 
Reported: 2007-04-18 05:24 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-09-01 21:35 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-04-18 05:24:29 UTC
The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-02 11:16:08 UTC
net-mail any news on this one?
Comment 2 Fernando J. Pereda (RETIRED) gentoo-dev 2007-05-08 19:23:11 UTC
Ouch... helps if I'm actually CCed :P

I'll see if upstream has released something related to this. Though I'm a bit busy these days so I'd apreciate if someone does it.

Cheers.

- ferdy
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-10 08:09:24 UTC
ferdy, any news on this one?
Comment 4 Fernando J. Pereda (RETIRED) gentoo-dev 2007-06-10 11:59:19 UTC
Sorry for the delay, I'm in exams period and haven't paid lots of attention to Gentoo these days.

Mutt-1.5.16 has just been released with a fix for this. I'll provide an updated ebuild soon.

- ferdy
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-16 06:28:57 UTC
ferdy any news on this one?
Comment 6 Fernando J. Pereda (RETIRED) gentoo-dev 2007-06-16 18:57:51 UTC
I have everything ready, but the sidebar patch hasn't been updated by its upstream. I'm currently uploading the patchset to the mirrors so it is ready once the sidebar patch is ready.

- ferd
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-16 19:40:43 UTC
Thanks for the stats update. Please post again once the ebuild is committed.
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-07-01 02:14:55 UTC
Ferdy, any news here?
Comment 9 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-14 22:32:52 UTC
any news here?
Comment 10 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-01 12:25:35 UTC
ferdy/net-mail, what's the status here?
Comment 11 Fernando J. Pereda (RETIRED) gentoo-dev 2007-08-08 09:42:59 UTC
The status is that I've been away and not every patch was ready when I wasn't away. The hard part of the job was done as stated in comment #6 so anyone could've finished it during my month off.

Anyway, everything should be ready now and I commited mail-client/mutt-1.5.16 a couple of minutes ago.

- ferdy
Comment 12 Torsten Veller (RETIRED) gentoo-dev 2007-08-08 10:00:29 UTC
(In reply to comment #6)
> I have everything ready, but the sidebar patch hasn't been updated by its
> upstream. I'm currently uploading the patchset to the mirrors so it is ready
> once the sidebar patch is ready.

(In reply to comment #11)
> The hard part of the job was done as stated in comment #6 so anyone
> could've finished it during my month off.

I wanted to bump it but the patches were already removed/cleaned from the mirrors again.
Hint: The patchset must be uploaded again.
Comment 13 Fernando J. Pereda (RETIRED) gentoo-dev 2007-08-08 10:05:28 UTC
Shite... forgot that. I'll do it in a minute. Thanks Torsten.

- ferdy
Comment 14 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-08-21 06:15:27 UTC
Ferdy, any news here?
Comment 15 Fernando J. Pereda (RETIRED) gentoo-dev 2007-08-21 06:27:43 UTC
Well... mutt-1.5.16 has been on the tree with a fix since:

---8<---
Comment  #11 From Fernando J. Pereda  2007-08-08 09:42:59 0000 
---8<---

That is, thirteen days. Also, stabilization of that version has been handled in bug #178003 and all security supported archs already marked it as such.

Is there anything I'm missing?

- ferdy
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-08-21 20:32:03 UTC
Sorry ferdy I forgot about the other bug.
Comment 17 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-01 21:35:47 UTC
finally closing without GLSA wrt the discussion on bug 178003, feel free to reopen  if you disagree.