Family: Red Hat Local Security Checks --> Category: infos
RHSA-2005-823: fetchmail Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the fetchmail packages
Detailed Explanation for this Vulnerability Test
Updated fetchmail packages that fix insecure configuration file creation is
This update has been rated as having low security impact by the Red Hat
Security Response Team.
Fetchmail is a remote mail retrieval and forwarding utility.
A bug was found in the way the fetchmailconf utility program writes
configuration files. The default behavior of fetchmailconf is to write a
configuration file which may be world readable for a short period of time.
This configuration file could provide passwords to a local malicious
attacker within the short window before fetchmailconf sets secure
permissions. The Common Vulnerabilities and Exposures project has assigned
the name CVE-2005-3088 to this issue.
Users of fetchmail are advised to upgrade to these updated packages, which
contain a backported patch which resolves this issue.
Solution : http://rhn.redhat.com/errata/RHSA-2005-823.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.