SB2015021501 - Data Handling in Apache Commons Email
Published: February 15, 2015 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Data Handling (CVE-ID: CVE-2015-1574)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.
Remediation
Install update from vendor's website.
References
- http://hmarco.org/bugs/google_email_app_4.2.2_denial_of_service.html
- http://openwall.com/lists/oss-security/2015/02/10/9
- http://openwall.com/lists/oss-security/2015/02/12/15
- http://packetstormsecurity.com/files/130388/Google-Email-4.4.2.0200-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2015/Feb/58
- http://www.securityfocus.com/archive/1/534703/100/0/threaded