Debian Security Advisory DSA 468-1                     [email protected]                             Matt Zimmerman
March 24th, 2004               
- --------------------------------------------------------------------------

Package        : emil
Vulnerability  : several
Problem-Type   : local/remote
Debian-specific: no
CVE Ids        : CAN-2004-0152 CAN-2004-0153

Ulf Harnhammar discovered a number of vulnerabilities in emil, a
filter for converting Internet mail messages.  The vulnerabilities
fall into two categories:

 - CAN-2004-0152 - Buffer overflows in (1) the encode_mime function,
   (2) the encode_uuencode function, (3) the decode_uuencode
   function.  These bugs could allow a carefully crafted email message
   to cause the execution of arbitrary code supplied with the message
   when it is acted upon by emil.

 - CAN-2004-0153 - Format string bugs in statements which print
   various error messages.  The exploit potential of these bugs has
   not been established, and is probably configuration-dependent.

For the stable distribution (woody) these problems have been fixed in
version 2.1.0-beta9-11woody1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you update your emil package.

Upgrade Instructions
wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody
- --------------------------------

