Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: 172-2 Urgent: Fetchmail Buffer Overflow Vulnerability Alert

debian
Calendar Grey October 8, 2002
Debian Logo
Various flaws in Fetchmail could allow remote attackers to execute arbitrary code, potentially leading to the attainment of elevated privileges.
There are several buffer overflows and a broken boundary check within fetchmail

Summary

Package : fetchmail, fetchmail-ssl
Vulnerability : buffer overflows
Problem-Type : remote
Debian-specific: no

Stefan Esser discovered several buffer overflows and a broken boundary
check within fetchmail. If fetchmail is running in multidrop mode
these flaws can be used by remote attackers to crash it or to execute
arbitrary code under the user id of the user running fetchmail.
Depending on the configuration this even allows a remote root
compromise.

These problems have been fixed in version 5.9.11-6.1 for both
fetchmail and fetchmail-ssl for the current stable distribution
(woody), in version 5.3.3-4.2 for fetchmail for the old stable
distribution (potato) and in version 6.1.0-1 for both fetchmail and
fetchmail-ssl for the unstable distribution (sid). There are no
fetchmail-ssl packages for the old stable distribution (potato) and
thus no updates.

We recommend that you upgrade your fetchmail packages immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will ins...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here