Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2001:054: imap Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the imap package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2001:054 (imap).
Several buffer overflow vulnerabilities have been found in the UW-IMAP package
by the authors and independant groups. These vulnerabilities can be exploited
only once a user has authenticated which limits the extent of the vulnerability
to a remote shell with that user's permissions. On systems where the user
already has a shell, nothing new will be provided to that user, unless the user
has only local shell access. On systems where the email accounts do not provide
shell access, however, the problem is much greater.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2001:054
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.