Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:139: cyrus-imapd Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the cyrus-imapd package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:139 (cyrus-imapd).
A number of vulnerabilities in the Cyrus-IMAP server were found by Stefan
Esser. Due to insufficient checking within the argument parser of the 'partial'
and 'fetch' commands, a buffer overflow could be exploited to execute arbitrary
attacker-supplied code. Another exploitable buffer overflow could be triggered
in situations when memory allocation files.
The provided packages have been patched to prevent these problems.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:139
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.