LWN.net Logo

rPath alert rPSA-2006-0084-1 (fetchmail)

From:  "Justin M. Forbes" <jmforbes@rpath.com>
To:  security-announce@lists.rpath.com, update-announce@lists.rpath.com
Subject:  rPSA-2006-0084-1 fetchmail
Date:  Fri, 26 May 2006 19:39:14 -0400
Cc:  full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, lwn@lwn.net

rPath Security Advisory: 2006-0084-1 Published: 2006-05-26 Products: rPath Linux 1 Rating: Minor Exposure Level Classification: User Non-deterministic Weakness Updated Versions: fetchmail=/conary.rpath.com@rpl:devel//1/6.2.5.5-0.1-1 References: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://bugs.rpath.com/show_bug.cgi?id=1170 Description: Previous versions of fetchmail, when talking to a hostile (possibly compromised) mail server, are vulnerable to possible denial of service or user compromise. Because a hostile or compromised mail server can take other actions on the user's behalf and has been provided with user authentication data, this individual security update can provide only limited protection against hostile or compromised servers, and does not and cannot protect against attacks such as theft of authentication information or email data by a hostile or compromised mail server.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds