Lucene search

K
gentooGentoo FoundationGLSA-200503-26
HistoryMar 20, 2005 - 12:00 a.m.

Sylpheed, Sylpheed-claws: Message reply overflow

2005-03-2000:00:00
Gentoo Foundation
security.gentoo.org
7

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

0.055 Low

EPSS

Percentile

93.3%

Background

Sylpheed is a lightweight email client and newsreader. Sylpheed-claws is a ‘bleeding edge’ version of Sylpheed.

Description

Sylpheed and Sylpheed-claws fail to properly handle non-ASCII characters in email headers when composing reply messages.

Impact

An attacker can send an email containing a malicious non-ASCII header which, when replied to, would cause the program to crash, potentially allowing the execution of arbitrary code with the privileges of the user running the software.

Workaround

There is no known workaround at this time.

Resolution

All Sylpheed users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=mail-client/sylpheed-1.0.3"

All Sylpheed-claws users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=mail-client/sylpheed-claws-1.0.3"
OSVersionArchitecturePackageVersionFilename
Gentooanyallmail-client/sylpheed< 1.0.3UNKNOWN
Gentooanyallmail-client/sylpheed-claws< 1.0.3UNKNOWN

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

0.055 Low

EPSS

Percentile

93.3%