Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 181099 - mail-filter/amavisd-new file Integer Underflow and Denial of Service (CVE-2007-2026 CVE-2007-2799)
Summary: mail-filter/amavisd-new file Integer Underflow and Denial of Service (CVE-200...
Status: RESOLVED DUPLICATE of bug 174217
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/25578/
Whiteboard: B1 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-06-06 16:30 UTC by Lars Hartmann
Modified: 2007-06-07 11:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2007-06-06 16:30:49 UTC
A vulnerability and a security issue have been reported in Amavis, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.

1) An integer underflow error in the "file" utility can be exploited to cause a heap-based buffer overflow.

For more information:
SA24548

2) The problem is caused due to certain regular expressions in "file", which can consume all available CPU resources when identifying a specially crafted file.

For more information:
SA24918

Solution:
The vendor recommends updating to file version 4.21 or later and editing the "magic" file (see vendor advisory for details).

Provided and/or discovered by:
Reported by the vendor.

Original Advisory:
http://www.amavis.org/security/asa-2007-3.txt

Other References:
SA24548:
http://secunia.com/advisories/24548/

SA24918:
http://secunia.com/advisories/24918/

Reproducible: Always
Comment 1 Lars Hartmann 2007-06-06 16:34:35 UTC
maintainers - please advise and bump as necessary
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-06 20:02:06 UTC
AFAIK amavisd-new doesn't bundle the file. The advisory is just to warn amavisd-new users to upgrade sys-apps/file.

*** This bug has been marked as a duplicate of bug 179583 ***
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2007-06-07 00:46:13 UTC
Not really a dupe. Point 4 in the linked advisory (CVE-2007-2026) is not fixed with 4.21.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-07 11:41:22 UTC
Well the CVE-2007-2026 issue was fixed on bug #174217, so now another dupe :-)

Feel free to reopen if I missed anything.

*** This bug has been marked as a duplicate of bug 174217 ***