|
|
| |
|
| |
fetchmail: arbitrary code execution
| Package(s): | fetchmail |
CVE #(s): | CVE-2010-0562
|
| Created: | February 16, 2010 |
Updated: | June 2, 2010 |
| Description: |
From the Mandriva advisory:
The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13,
when running in verbose mode on platforms for which char is signed,
allows remote attackers to cause a denial of service (application
crash) or possibly execute arbitrary code via an SSL X.509 certificate
containing non-printable characters with the high bit set, which
triggers a heap-based buffer overflow during escaping. |
| Alerts: |
|
( Log in to post comments)
|
|
|