积极预防 及时发现
快速响应 力保恢复
pgp4pine 存在堆溢出缺陷 (Other,缺陷)
发布时间:2003-03-17 信息来源:管理员

涉及程序: pgp4pine 描述: pgp4pine 存在堆溢出缺陷允许攻击者执行任意指令 详细: pgp4pine是一款用于Pine的邮件解密/加密/签名/查证工具,对Pine接收到的邮件进行解析,并查询其PGP信息。 pgp4pine在阅读接收到的邮件之前将对所有邮件进行解析(缺省标配),并查询来自寄信人的PGP标记和信息。pgp4pine调用menus.c: void fileVerifyDecryptMenu(char *inFile,char *outFile)函数对接收的邮件进行效验,并利用下列代码查询邮件的每行字符串: <...> char readline ; (where defines.h:#define CONSOLE_IO_LINE_LENGTH 256) <...> do { fertig=0; while (!fertig) { if ((c=getc(fin))==EOF) { outFile=inFile; /* this usually is not executed, EOF breaks directly */ return; } else if ((readline =c) == `\n`) { readline =\`\\0\`; fertig=1; } } fertig=0; if (strncmp(\"-----BEGIN PGP SIGNED\",readline,20)==0) { /* got signed message */ fclose(fin); while (fileVerify(inFile,outFile) > 0); /* =1: Repeat */ fertig=1; } else if (strncmp("-----BEGIN PGP",readline,14)==0) { /* got another type of PGP message (encrypted, keys ...) */ fclose(fin); fileDecrypt(inFile,outFile); waitForReturn(); fertig=1; } else i=0; /* Got waste line, reset i */ } while (!fertig); <...> 由于程序没有正确的检测索引“i”内部的readline<>函数,当某行字符串长度超过256字节时,将产生堆溢出。 利用该缺陷,通过向用户发送精心构造的恶意邮件,攻击者能在用户的机器上执行任意代码。 攻击方法: 暂无有效攻击代码 解决方案: 目前厂商尚未发布补丁,建议用户随时关注厂商站点: http://pgp4pine.flatline.de/ 临时解决方案: 暂时禁用pgp4pine,并使用其他PGP程序替代pgp4pine