LWN.net Logo

Advertisement

Front, Kernel, Security, Distributions, Development. See your byline here on LWN.net.

Advertise here

Gentoo alert 200305-12 (uw-imapd)

From:  Daniel Ahlberg <aliz@gentoo.org>
To:  gentoo-announce@gentoo.org
Subject:  GLSA: uw-imapd (200305-12)
Date:  Sun, 1 Jun 2003 13:54:25 +0200

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-12 - - - --------------------------------------------------------------------- PACKAGE : uw-imapd SUMMARY : buffer overflow DATE : 2003-06-01 11:54 UTC EXPLOIT : remote VERSIONS AFFECTED : <uw-imapd-2002d FIXED VERSION : >=uw-imapd-2002d CVE : - - - --------------------------------------------------------------------- - From advisory: "UW-imapd can also act as IMAP client, allowing user to connect to specified server. It is disabled for anonymous users, but allowed for everyone else (even with closedBox, blackBox or restrictBox enabled). So exploiting it could give you access to the system as the logged in user." Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=105294024124163&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running net-mail/uw-imapd upgrade to uw-imapd-2002d as follows emerge sync emerge uw-imapd emerge clean - - - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz prez@gentoo.org - - - --------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE+2elufT7nyhUpoZMRAmlOAKCitC0oKI/kdV6MvKwGUoa5j5K3AwCgvY+8 aMWvvFF6iPRICVvdY7/ipYc= =nEu+ -----END PGP SIGNATURE-----


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds