[Japanese]
|
JVNDB-2009-000011
|
Becky! Internet Mail buffer overflow vulnerability
|
Becky! Internet Mail contains a buffer overflow vulnerability.
Becky! Internet Mail is an email client software. Becky! Internet Mail contains a buffer overflow vulnerability as it does not properly handle read receipt requests.
Yuji Ukai of Fourteenforty Research Institute, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 6.8 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
|
|
RIMARTS
- Becky! Internet Mail Ver.2.48.02 and eariler
|
|
If the user views a specially crafted email and allows a read receipt to be sent, arbitrary code may be executed.
|
[Update the Software]
Apply the latest updates provided by the vendor.
[Workarounds]
As a workaround to this vulnerability, in "General Setup", modify the setting for "How to respond to a request for 'read receipt'" to "ignore" until an update is completed.
|
RIMARTS
|
- Buffer Errors(CWE-119) [IPA Evaluation]
|
- CVE-2009-0569
|
- JVN : JVN#29641290
- National Vulnerability Database (NVD) : CVE-2009-0569
- IPA SECURITY ALERTS : Security Alert for Becky! Internet Mail Vulnerability
- Secunia Advisory : SA33892
- SecurityFocus : 33756
- ISS X-Force Database : 48684
- JVN iPedia (Japanese) : JVNDB-2009-000011
|
- [2009/02/12]
Web page published
|