J-Security Center

Title: HyperMail Remote Command Execution Vulnerability

Severity: HIGH

Description:

HyperMail is free, open-source mailing list software which will take e-mail and convert it to HTML.

HyperMail is prone to a vulnerability which may allow a user to execute arbitrary SSI commands on a host.

Attachments sent in e-mail are not modified in any way before being archived by HyperMail. This becomes an issue if SSI is enabled on the host running HyperMail, as it is possible to upload a file with an SSI extension, such as .shtml, which contains server-side includes that will be executed when the attachment is requested.

However, the root of this issue is that a user may send an attachment which an arbitrary file extension, which will then be archived. Other content may be executed on the server as a result of this vulnerability.

Affected Products:

  • Debian Linux 3.0.0
  • Debian Linux 3.0.0 alpha
  • Debian Linux 3.0.0 arm
  • Debian Linux 3.0.0 hppa
  • Debian Linux 3.0.0 ia-32
  • Debian Linux 3.0.0 ia-64
  • Debian Linux 3.0.0 m68k
  • Debian Linux 3.0.0 mips
  • Debian Linux 3.0.0 mipsel
  • Debian Linux 3.0.0 ppc
  • Debian Linux 3.0.0 s/390
  • Debian Linux 3.0.0 sparc
  • HyperMail HyperMail 2.0.0.0
  • HyperMail HyperMail 2.1.0.0
  • HyperMail HyperMail 2.1.1
  • HyperMail HyperMail 2.1.2
  • HyperMail HyperMail 2.1.3

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.