LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

Gentoo alert fetchmail-20021001 (fetchmail)

From:  Daniel Ahlberg <aliz@gentoo.org>
To:  bugtraq@securityfocus.com
Subject:  GLSA: fetchmail
Date:  Tue, 1 Oct 2002 11:41:47 +0200

-------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT -------------------------------------------------------------------- PACKAGE :fetchmail SUMMARY :remote vulnerabilities DATE :2002-10-01 09:30 UTC -------------------------------------------------------------------- OVERVIEW Stefan Esser from e-matters has discovered several buffer overflows and a broken boundary check within Fetchmail. DETAIL If Fetchmail is running in multidrop mode these flaws can be used by remote attackers to crash it or to execute arbitrary code with the permissions of the user running fetchmail. Depending on the configuration this allows a remote root compromise. Read the full advisory at http://security.e-matters.de/advisories/032002.html SOLUTION It is recommended that all Gentoo Linux users who are running net-mail/fetchmai-0.59.14 and earlier update their systems as follows: emerge rsync emerge fetchmail emerge clean -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz --------------------------------------------------------------------


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.