Bug 821416 (CVE-2006-0138)

Summary: CVE-2006-0138 amsn: DoS (client hang, termination of client's IM session) via repeatedly sending crafted data to default file-transfer port
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: sander
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20060101,reported=20120514,source=gentoo,cvss2=2.6/AV:N/AC:H/Au:N/C:N/I:N/A:P,fedora-all/amsn=affected
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 821435    
Bug Blocks:    

Description Jan Lieskovsky 2012-05-14 08:41:08 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2006-0138 to the following vulnerability:

aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891). 

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0138
[2] http://www.osvdb.org/22186
[3] https://bugs.gentoo.org/show_bug.cgi?id=415861
[4] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=557754

Reproducer:
[5] http://www.securiteam.com/exploits/5JP090KHFQ.html

Upstream ticket:
[6] http://sourceforge.net/tracker/?func=detail&aid=2921641&group_id=54091&atid=472655
Comment 1 Jan Lieskovsky 2012-05-14 08:45:54 EDT
I have tried to test / reproduce this issue on Fedora-15 / Fedora-16 versions (based on [5]), but unable to reproduce it, because according to aMSN -> Account -> Preferences -> Connection tab -> "File transfer, peer-to-peer and NAT settings" and "Test port" button my connection is:

"You are firewalled or behind a router"

thus running the ./dos.pl from [5] returns 'Connection refused' for me. But since there doesn't seem to be an upstream patch for this issue yet, I would say Fedora-15 and Fedora-16 amsn package versions are still vulnerable to this issue.

Please schedule an update once there is final upstream patch version available.
Comment 2 Jan Lieskovsky 2012-05-14 09:22:23 EDT
Created amsn tracking bugs for this issue

Affects: fedora-all [bug 821435]
Comment 3 Fedora Update System 2012-08-25 20:22:20 EDT
amsn-0.98.9-4.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.