|
Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200403-10] Fetchmail 6.2.5 fixes a remote DoS Vulnerability Scan
Vulnerability Scan Summary Fetchmail 6.2.5 fixes a remote DoS
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200403-10
(Fetchmail 6.2.5 fixes a remote DoS)
Fetchmail versions 6.2.4 and earlier can be crashed by sending a
specially-crafted email to a fetchmail user. This problem occurs because
Fetchmail does not properly allocate memory for long lines in an incoming
email.
Impact
Fetchmail users who receive a malicious email may have their fetchmail
program crash.
Workaround
While a workaround is not currently known for this issue, all users are advised to upgrade to the latest version of fetchmail.
References:
http://xforce.iss.net/xforce/xfdb/13450
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0792
Solution:
Fetchmail users should upgrade to version 6.2.5 or later:
# emerge sync
# emerge -pv ">=net-mail/fetchmail-6.2.5"
# emerge ">=net-mail/fetchmail-6.2.5"
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.
|