Debian: New mailutils packages fix several vulnerabilities

Date 03 Jun 2005
Posted By Joe Shakespeare
Updated package.
Debian Security Advisory DSA 732-1
June 3rd, 2005                
Package        : mailutils
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE ID         : CAN-2005-1520 CAN-2005-1521 CAN-2005-1522 CAN-2005-1523

"infamous41md" discovered several vulnerabilities in the GNU mailutils
package which contains utilities for handling mail.  These problems
can lead to a denial of service or the execution of arbitrary code.
The Common Vulnerabilities and Exposures project identifies the
following vulnerabilities.


    Buffer overflow mail header handling may allow a remote attacker
    to execute commands with the privileges of the targeted user.


    Combined integer and heap overflow in the fetch routine can lead
    to the execution of arbitrary code.


    Denial of service in the fetch routine.


    Format string vulnerability can lead to the execution of arbitrary

For the stable distribution (woody) these problems have been fixed in
version 20020409-1woody2.

For the testing distribution (sarge) these problems have been fixed in
version 0.6.1-4.

For the unstable distribution (sid) these problems have been fixed in
version 0.6.1-4.

We recommend that you upgrade your mailutils packages.



Debian GNU/Linux 3.0 alias woody
For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.


