A remote overflow exists in several mail user agents (MUAs). The MUAs fail to properly cope with tags that identify an attachment, resulting in a buffer overflow. With a specially crafted e-mail, an attacker can potentially execute arbitrary code resulting in a loss of confidentiality and/or integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
Technical
According to Netscape, this vulnerability does not apply to versions of Communicator for Windows or Macintosh.
Solution
Upgrade to the proper version depending on the MUA installed, according to the vendor advisories, as they have been reported to fix this vulnerability. An upgrade is required as there are no known client side workarounds.
Sendmail has implemented a patch that can be implemented as a workaround if used as an MTA. The patch is listed in the external references.