Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2001:072: fetchmail Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the fetchmail package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2001:072 (fetchmail).
A vulnerability was found by Salvatore Sanfilippo in both the IMAP and POP3 code
of fetchmail where the input is not verified and no bounds checking is done.
This can be exploited by a remote attacker to write arbitrary data into memory.
The attacker must have control of the mail server the client is connecting to
via fetchmail in order to exploit this vulnerability.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2001:072
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.