Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 200289

Summary: dev-java/sun-javamail Remote Denial of Service (CVE-2007-6059)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: minor CC: java
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://archives.neohapsis.com/archives/bugtraq/2007-11/0239.html
Whiteboard: B3 [upstream]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2007-11-25 15:28:40 UTC
CVE-2007-6059 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6059):
  Javamail does not properly handle a series of invalid login attempts in which
  the same e-mail address is entered as username and password, and the domain
  portion of this address yields a Java UnknownHostException error, which
  allows remote attackers to cause a denial of service (connection pool
  exhaustion) via a large number of requests, resulting in a SQLNestedException.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-11-25 15:29:39 UTC
Java herd, please advise.
Comment 2 Krzysztof Pawlik (RETIRED) gentoo-dev 2007-11-25 17:22:24 UTC
Looks like a bug not in sun-javamail (which is just a library for SMTP, POP3 and IMAP) but in some webmail. Especially the 'com.example.util.dao..' package - it's not a part of sun-javamail.
Comment 3 Krzysztof Pawlik (RETIRED) gentoo-dev 2007-11-25 17:29:28 UTC
Also: sun-javamail or gnu-javamail? Probably we have to wait until more details are available. There's nothing about this issue on changelog for sun-javamail 1.4.1: http://java.sun.com/products/javamail/CHANGES.txt
Comment 4 Krzysztof Pawlik (RETIRED) gentoo-dev 2007-11-25 18:12:19 UTC
Robert sent an email to Thet Aung Min Latt for clarification.
Comment 5 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-11-26 15:06:59 UTC
That CVE needs to be updated and is SEVERELY misleading.  Javamail has no SQL pieces or etc. Javamail provides NO means to login via the web, or any means to log in. Short of passing credentials to a IMAP or POP server via it's API. Which that's all it is a Java API for sending and receiving email.

Obviously someone has used this in a webmail app that has some vulnerabilities but failed to disclose that. Instead they blamed an underlying technology that is hardly responsible. I fail to see how this effects Sun or Sun's Javamail.

I recommend we close as invalid. Even if the webmail is vulnerable, I doubt it's packaged and available on Gentoo. Since we really have no packaged Java webapps atm. 
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-01-15 15:46:00 UTC
CVE was disputed, quoting:
Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products."

Closing INVALID.