fetchmail denial of service CVE-2008-2711

Bug #240549 reported by Emanuele Gentili
262
Affects Status Importance Assigned to Milestone
fetchmail (Suse)
Fix Released
High
fetchmail (Ubuntu)
Fix Released
Low
Scott Kitterman
Dapper
Won't Fix
Low
Unassigned
Feisty
Won't Fix
Low
Unassigned
Gutsy
Won't Fix
Low
Unassigned
Hardy
Won't Fix
Low
Unassigned
Intrepid
Fix Released
Low
Scott Kitterman

Bug Description

fetchmail 6.3.8 and earlier, when running in -v -v mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which is not properly handled when using vsnprintf to format log messages.

Tags: patch

Related branches

CVE References

Changed in fetchmail:
assignee: nobody → emgent
importance: Undecided → High
status: New → In Progress
Changed in fetchmail:
status: Unknown → Fix Released
Revision history for this message
Till Ulen (tillulen) wrote :

Trying to link this bug to CVE-2008-2711 (the web UI for that doesn't seem to work).

Revision history for this message
Emanuele Gentili (emgent) wrote :
Revision history for this message
Till Ulen (tillulen) wrote : Re: [Bug 240549] Re: fetchmail denial of service CVE-2008-2711

On Fri, Jun 20, 2008 at 03:18, Emanuele Gentili wrote:
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2711

I meant using the link "Link to CVE" in the Actions menu on the left
which adds an appropriate reference to this bug's metadata and makes
it findable in the Launchpad CVE tracker
<https://bugs.launchpad.net/bugs/cve>.

See bug 241435 in Launchpad.

Revision history for this message
Kees Cook (kees) wrote :

Once a qa-regression-testing test has been written for this update, we can do the cross-release regression testing done, and get it published. Thanks!

Changed in fetchmail:
importance: High → Low
assignee: nobody → emgent
importance: Undecided → Low
status: New → Triaged
assignee: nobody → emgent
importance: Undecided → Low
status: New → Triaged
status: In Progress → Triaged
assignee: nobody → emgent
importance: Undecided → Low
status: New → Triaged
assignee: nobody → emgent
importance: Undecided → Low
status: New → Triaged
Revision history for this message
Emanuele Gentili (emgent) wrote :

debdiff retired for now.

Wrinting qa-regression-testing script for test upstream fix.

Revision history for this message
Emanuele Gentili (emgent) wrote :
Revision history for this message
Emanuele Gentili (emgent) wrote :
Revision history for this message
Michael Casadevall (mcasadevall) wrote :

Here's a patch to correct this security bug in intrepid.

Changed in fetchmail:
status: Triaged → In Progress
Revision history for this message
Scott Kitterman (kitterman) wrote :

Grabbing to look at sponsoring for Intrepid.

Changed in fetchmail:
assignee: emgent → kitterman
Changed in fetchmail:
status: In Progress → Fix Committed
Revision history for this message
Scott Kitterman (kitterman) wrote :

Not Fix Committed. Soyuz ate the upload twice. Waiting to find out what to do ...

Changed in fetchmail:
status: Fix Committed → In Progress
Changed in fetchmail:
status: In Progress → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package fetchmail - 6.3.8-11ubuntu3

---------------
fetchmail (6.3.8-11ubuntu3) intrepid; urgency=low

  * SECURITY FIX for CVE-2008-2711 (LP: #240549)
    - Corrects a denial of service attack that can crash fetchmail when
      running in -v -v mode via malformed mail messages with long headers
  * patches/06_fix_CVE-2008-2711_DoS.patch
    - corrects CVE-2008-2711

 -- Michael Casadevall <email address hidden> Tue, 21 Oct 2008 08:05:46 -0400

Changed in fetchmail:
status: Fix Committed → Fix Released
Revision history for this message
LumpyCustard (orangelumpycustard) wrote :

Please close for Feisty as Won't Fix? This goes for all the other Feisty bugs.

Revision history for this message
Hew (hew) wrote :

Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued for this release. Marking Feisty as Won't Fix.

Changed in fetchmail:
status: Triaged → Won't Fix
Revision history for this message
Sergio Zanchetta (primes2h) wrote :

The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

Changed in fetchmail (Ubuntu Gutsy):
status: New → Won't Fix
Revision history for this message
Artur Rona (ari-tczew) wrote :
Revision history for this message
Thierry Carrez (ttx) wrote :

Unsubscribing sponsors, as I see nothing ready to be sponsored here...
Please resubscribe sponsors when you have a debdiff or a branch ready for a given release ?

tags: added: patch
Revision history for this message
Artur Rona (ari-tczew) wrote :

Dapper is ignored, so I'm closing the task.

Changed in fetchmail (Ubuntu Dapper):
assignee: Emanuele Gentili (emgent) → nobody
status: Triaged → Invalid
Kees Cook (kees)
Changed in fetchmail (Ubuntu Dapper):
status: Invalid → Won't Fix
Changed in fetchmail (Ubuntu Feisty):
assignee: Emanuele Gentili (emgent) → nobody
Changed in fetchmail (Ubuntu Gutsy):
assignee: Emanuele Gentili (emgent) → nobody
importance: Undecided → Low
Artur Rona (ari-tczew)
Changed in fetchmail (Ubuntu Hardy):
assignee: Emanuele Gentili (emgent) → Artur Rona (ari-tczew)
status: Triaged → In Progress
Revision history for this message
Scott Kitterman (kitterman) wrote :

Not a GUI app. Dapper is supported for another year.

Changed in fetchmail (Ubuntu Dapper):
status: Won't Fix → Confirmed
Artur Rona (ari-tczew)
Changed in fetchmail (Ubuntu Hardy):
assignee: Artur Rona (ari-tczew) → nobody
status: In Progress → New
Kees Cook (kees)
Changed in fetchmail (Ubuntu Hardy):
status: New → Triaged
Changed in fetchmail (Ubuntu Dapper):
status: Confirmed → Triaged
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

According to http://www.openwall.com/lists/oss-security/2008/06/13/1, -vv is used for debugging only and is not used in non-interactive settings. This bug may be fixed in a future update of fetchmail, at which point the status will be updated. Marking "Won't Fix" for now.

Changed in fetchmail (Ubuntu Dapper):
status: Triaged → Won't Fix
Changed in fetchmail (Ubuntu Hardy):
status: Triaged → Won't Fix
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

To clarify:

Artur, thank you very much for your patch. This vulnerability is considered negligible so your patches don't qualify for a security update at this time. If/when a more serious vulnerability is found in fetchmail, your patch can be rolled into that update and this bug's status will be adjusted. Updates are not provided for very minor issues as any update can potentially create work for administrators and users (for testing before a rollout) as well as risk regression. The vulnerability must outweigh the risks of regression and time required by administrators.

Thanks again

Changed in fetchmail (Suse):
importance: Unknown → High
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.