LWN.net Logo

fetchmail: arbitrary code execution

Package(s):fetchmail CVE #(s):CVE-2010-0562
Created:February 16, 2010 Updated:June 2, 2010
Description: From the Mandriva advisory:

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.

Alerts:
Gentoo 201006-12 2010-06-01
Fedora FEDORA-2010-3800 2010-03-06
SuSE SUSE-SR:2010:005 2010-02-23
Mandriva MDVSA-2010:037 2010-02-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds