Vulnerability Scanning Solutions, LLC.
Our Process
What We Scan For
Sample Report
Client List
Contact Us
What We Scan For
Family: Ubuntu Local Security Checks --> Category: infos

USN215-1 : fetchmail vulnerability Vulnerability Scan

Vulnerability Scan Summary
fetchmail vulnerability

Detailed Explanation for this Vulnerability Test

Synopsis :

These remote packages are missing security patches :
- fetchmail
- fetchmail-ssl
- fetchmailconf

Description :

Thomas Wolff and Miloslav Trmac discovered a race condition in the
fetchmailconf program. The output configuration file was initially
created with insecure permissions, and secure permissions were applied
after writing the configuration into the file. During this time, the
file was world readable on a standard system (unless the user manually
tightened his umask setting), which could expose email passwords to
local users.

Solution :

Upgrade to :
- fetchmail-6.2.5-13ubuntu3.1 (Ubuntu 5.10)
- fetchmail-ssl-6.2.5-13ubuntu3.1 (Ubuntu 5.10)
- fetchmailconf-6.2.5-13ubuntu3.1 (Ubuntu 5.10)

Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.


P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.