Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 197679 (CVE-2007-5740) - net-mail/perdition <1.17.1 Format String Vulnerability (CVE-2007-5740)
Summary: net-mail/perdition <1.17.1 Format String Vulnerability (CVE-2007-5740)
Status: RESOLVED FIXED
Alias: CVE-2007-5740
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/27458/
Whiteboard: ~1 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-10-31 20:21 UTC by Tobias Heinlein (RETIRED)
Modified: 2008-01-05 02:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Heinlein (RETIRED) gentoo-dev 2007-10-31 20:21:20 UTC
Bernhard Mueller has reported a vulnerability in Perdition, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

The vulnerability is caused due to the Perdition IMAP server incorrectly checking for malicious format string specifiers contained within IMAP requests. This can be exploited to bypass the format string check by inserting a zero byte in an IMAP request.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in versions prior to 1.17.1.

Solution:
Update to version 1.17.1.
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2007-10-31 20:25:54 UTC
Net-mail, please advise or create an updated ebuild.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-11-05 19:31:04 UTC
Net-mail, please advise.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2007-11-15 00:37:04 UTC
Net-mail, ferdy usually took care of this ebuild, but is away at the moment.

Can you please do this ebuild bump?
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-12-08 23:53:05 UTC
(In reply to comment #3)
> Net-mail, ferdy usually took care of this ebuild, but is away at the moment.
> 
> Can you please do this ebuild bump?
> 

*ping*
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-01-05 02:44:55 UTC
net-mail, I committed net-mail/perdition-1.17.1 as a non-maintainer bump since there was no movement on this bug for > 2 months. Hope you don't mind.