evolution-data-server: insufficient checking of NTLM authentication challenge packets
Published Mar 14, 2009
5.8
MEDIUMCVSS 2.0
EPSS 2.27%
Description
The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.
Affected products
No data.
- ≤ 2.24.5
- 2.25.92
No data.
Red Hat Enterprise Linux 3
evolution-0:1.4.5-25.el3
Fixed · RHSA-2009:0358
Red Hat Enterprise Linux 4
evolution-0:2.0.2-41.el4_7.2
Fixed · RHSA-2009:0355
Red Hat Enterprise Linux 4
evolution-data-server-0:1.0.2-14.el4_7.1
Fixed · RHSA-2009:0355
Red Hat Enterprise Linux 4
evolution28-evolution-data-server-0:1.8.0-37.el4_7.2
Fixed · RHSA-2009:0354
Red Hat Enterprise Linux 5
evolution-data-server-0:1.12.3-10.el5_3.3
Fixed · RHSA-2009:0354
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | evolution-0:1.4.5-25.el3 | Fixed | RHSA-2009:0358 |
| Red Hat Enterprise Linux 4 | evolution-0:2.0.2-41.el4_7.2 | Fixed | RHSA-2009:0355 |
| Red Hat Enterprise Linux 4 | evolution-data-server-0:1.0.2-14.el4_7.1 | Fixed | RHSA-2009:0355 |
| Red Hat Enterprise Linux 4 | evolution28-evolution-data-server-0:1.8.0-37.el4_7.2 | Fixed | RHSA-2009:0354 |
| Red Hat Enterprise Linux 5 | evolution-data-server-0:1.12.3-10.el5_3.3 | Fixed | RHSA-2009:0354 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (26)
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html vendor-advisoryx_refsource_SUSE
- http://mail.gnome.org/archives/release-team/2009-March/msg00096.html mailing-listx_refsource_MLIST
- http://osvdb.org/52673 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/34286 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34338 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34339 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34348 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34363 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35065 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35357 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1021845 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2009/dsa-1813 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:078 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2009-0354.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2009-0355.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2009-0358.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/34109 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/0716 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-0582 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487685 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49233 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-0582
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10081 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-0582
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00666.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00672.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.