Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200403-10 ] Fetchmail 6.2.5 fixes a remote DoS
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Bodhisattva
Bodhisattva


Joined: 13 Jun 2003
Posts: 4087
Location: Dresden, Germany

PostPosted: Wed Mar 31, 2004 10:09 am    Post subject: [ GLSA 200403-10 ] Fetchmail 6.2.5 fixes a remote DoS Reply with quote

Gentoo Linux Security Advisory

Title: Fetchmail 6.2.5 fixes a remote DoS (GLSA 200403-10)
Severity: normal
Exploitable: remote
Date: March 30, 2004
Bug(s): #37717
ID: 200403-10

Synopsis

Fetchmail versions 6.2.4 and earlier can be crashed by sending a specially-crafted email to a fetchmail user.

Background

Fetchmail is a utility that retrieves and forwards mail from remote systems using IMAP, POP, and other protocols.

Affected Packages

Package: net-mail/fetchmail
Vulnerable: <= 6.2.4
Unaffected: >= 6.2.5
Architectures: All supported architectures


Description

Fetchmail versions 6.2.4 and earlier can be crashed by sending a specially-crafted email to a fetchmail user. This problem occurs because Fetchmail does not properly allocate memory for long lines in an incoming email.

Impact

Fetchmail users who receive a malicious email may have their fetchmail program crash.

Workaround

While a workaround is not currently known for this issue, all users are advised to upgrade to the latest version of fetchmail.

Resolution

Fetchmail users should upgrade to version 6.2.5 or later:
Code:
# emerge sync
# emerge -pv ">=net-mail/fetchmail-6.2.5"
# emerge ">=net-mail/fetchmail-6.2.5"


References

ISS X-Force Listing
CVE Candidate (CAN-2003-0792)


Last edited by GLSA on Sun May 07, 2006 4:50 pm; edited 1 time in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum