Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian 3.0 DSA 468-1 Critical: emil Local And Remote Issues

debian
Calendar Grey March 26, 2004
Debian Logo
Ubuntu Security Warning USW 219-2: quinn multiple internal and external threats mitigated through recent patches.
Ulf Harnhammar discovered a number of vulnerabilities in emil, both various buffer overflows and format string bugs.

Summary

Ulf Harnhammar discovered a number of vulnerabilities in emil, a
filter for converting Internet mail messages. The vulnerabilities
fall into two categories:

- CAN-2004-0152 - Buffer overflows in (1) the encode_mime function,
(2) the encode_uuencode function, (3) the decode_uuencode
function. These bugs could allow a carefully crafted email message
to cause the execution of arbitrary code supplied with the message
when it is acted upon by emil.

- CAN-2004-0153 - Format string bugs in statements which print
various error messages. The exploit potential of these bugs has
not been established, and is probably configuration-dependent.

For the stable distribution (woody) these problems have been fixed in
version 2.1.0-beta9-11woody1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you update your emil package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the refere...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: emil

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here