|
Family: Fedora Local Security Checks --> Category: infos
Fedora Core 3 2005-614: fetchmail Vulnerability Scan
Vulnerability Scan Summary Check for the version of the fetchmail package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2005-614 (fetchmail).
Fetchmail is a remote mail retrieval and forwarding utility intended
for use over on-demand TCP/IP links, like SLIP or PPP connections.
Fetchmail supports every remote-mail protocol currently in use on the
Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6,
and IPSEC) for retrieval. Then Fetchmail forwards the mail through
SMTP so you can read it through your favorite mail client.
Install fetchmail if you need to retrieve mail over SLIP or PPP
connections.
Update Information:
A buffer overflow was discovered in fetchmail's POP3 client. A
malicious
server could cause fetchmail to execute arbitrary code.
The Common Vulnerabilities and Exposures project has assigned the name
CVE-2005-2355 to this issue.
All fetchmail users should upgrade to the updated package, which fixes
this issue.
Solution : http://www.fedoranews.org/blog/index.php?p=780
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|