|
ripMIME MIME Decoding Vulnerabilities
|
|
Secunia Advisory:
|
SA12515
|
|
|
Release Date:
|
2004-09-15
|
|
Popularity:
|
4,658 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | ripMIME 1.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
| | CVE reference: | CVE-2003-1015 CVE-2003-1016 CVE-2004-0051 CVE-2004-0052 CVE-2004-0161
|
|
Description: The vendor has acknowledged some vulnerabilities in ripMIME, which potentially can be exploited by malicious people to bypass filters.
The vulnerabilities are caused due to various errors within the MIME decoding when encountering multiple filename/content entries, missing separators, header comments, empty boundaries, and RFC2231 encoded filenames.
Successful exploitation may potentially allow bypassing certain email and content filters.
The vulnerabilities were reportedly discovered using a test suite developed by Martin O'Neal of Corsaire.
Solution: Update to version 1.4.0.0.
http://www.pldaniels.com/ripmime/downloads.php
Provided and/or discovered by: Martin O'Neal, Corsaire.
Original Advisory: NISCC:
http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Corsaire:
http://www.corsaire.com/advisories/c030804-003.txt
http://www.corsaire.com/advisories/c030804-004.txt
http://www.corsaire.com/advisories/c030804-005.txt
http://www.corsaire.com/advisories/c030804-006.txt
http://www.corsaire.com/advisories/c030804-008.txt
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
7th Oct, 2008
|
New advisories:
|
19 |
|
New vulnerabilities:
|
68 |
|
Updated advisories:
|
62 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|