Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] Novell/Ximian Evolution multiple text attachments DoS |
|---|---|
| Date: | Fri, 25 Feb 2005 19:45:32 -0500 |
================== =====Analysis===== ================== I just wanted to inform users of Ximian Evolution 2.0 software that there exists a way to temporarily DoS the local application and/or machine by attaching an absurd amount of .ezm files to a normal email. It seems that Evolution tries to interpret all these attachments and will actually display them if it determines they are text. The problem comes when Evolution is sent an email with say, greater than 1000 .ezm attachments, and the application tries to unroll them all before allowing you to do anything else within the application. These .ezm files are usually created by the EZ Mailing List Manager software, but one may custom design their own to execute the DoS attack. There seem to be other attachment types that can be used as well, as long as Evolution tries to unroll them for view in the message window. ================== ===Implications=== ================== The attack is not sophisticated and Evolution will eventually interpret all of the attachments -- but until that time (very long), it would appear to the user that the application has crashed and is unresponsive. A future attack method that exploits flaws in the attachment renderer could be combined with this DoS attack to confuse the user while running some malicious script in the background. ================== =====Affected===== ================== Tested on Evolution <=2.0.2 Note: higher versions may still be affected ================== =====Solution===== ================== Unknown for now. Will check out CVS, and if time, issue patch. -- Kristian Hermansen <khermansen@ht-technology.com>
signature.asc
Description: This is a digitally signed message part
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-Disclosure] More T-Mobile fall out..., security curmudgeon |
|---|---|
| Next by Date: | RE: [Full-Disclosure] Awake a modem with AT commands, Syed Imran Ali |
| Previous by Thread: | [Full-Disclosure] More T-Mobile fall out..., pingywon |
| Next by Thread: | RE: [lists] [Full-Disclosure] Novell/Ximian Evolution multiple text attachmentsDoS, Curt Purdy |
| Indexes: | [Date] [Thread] [Top] [All Lists] |