Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Slackware 8.1-10.2: 2006-207-01 Critical: Mutt Buffer Overflow

slackware
Calendar Grey July 26, 2006
Scroller Slackware
Gentoo unveils new vim updates to fix severe memory corruption flaw, enhancing SSH protocol protection. Keep informed!
New mutt packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix a possible security issue

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/mutt-1.4.2.2i-i486-1_slack10.2.tgz: Upgraded to mutt-1.4.2.2i. This release fixes CVE-2006-3242, a buffer overflow that could be triggered by a malicious IMAP server. [Connecting to malicious IMAP servers must be common, right? -- Ed.] For more details, see: https://www.cve.org/CVERecord?id=CVE-2006-3242 (* Security fix *)

Where Find New Packages

HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 8.1: ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/mutt-1.4.2.2i-i386-1_slack8.1.tgz
Updated package for Slackware 9.0: ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/mutt-1.4.2.2i-i386-1_slack9.0.tgz
Updated package for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/mutt-1.4.2.2i-i486-1_slack9.1.tgz
Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/mutt-1.4...

Read the Full Advisory

MD5 Signatures

Slackware 8.1 package: a28e088efe980f3b629fd291b3281eae mutt-1.4.2.2i-i386-1_slack8.1.tgz
Slackware 9.0 package: 2069ff5d3635106fc6f70f649a4ea51c mutt-1.4.2.2i-i386-1_slack9.0.tgz
Slackware 9.1 package: f662f9f3580261cf99e9c77a7386e8a0 mutt-1.4.2.2i-i486-1_slack9.1.tgz
Slackware 10.0 package: 550564cd80a3618ee80f30d2242c795e mutt-1.4.2.2i-i486-1_slack10.0.tgz
Slackware 10.1 package: c59433c5ca44d48d27ea29bcaabcf56e mutt-1.4.2.2i-i486-1_slack10.1.tgz
Slackware 10.2 package: 60561d151533a69efe59542db807bdcb mutt-1.4.2.2i-i486-1_slack10.2.tgz
Slackware -current package: 579d5974efdd071804ad5fbed5f1ab22 mutt-1.4.2.2i-i486-1.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg mutt-1.4.2.2i-i486-1_slack10.2.tgz