Security Advisory Format string bug fixed in exim

Advisory: RHSA-2001:078-14
Type: Security Advisory
Severity: N/A
Issued on: 2001-06-11
Last updated on: 2001-06-22
Affected Products: Powertools 6.2
Powertools 7.0
Powertools 7.1
OVAL: N/A
CVEs (cve.mitre.org): CVE-2001-0690

Details

A locally-exploitable format string bug, located in the code that handles
batch SMTP, has been fixed in exim.

A format string vulnerability has been found in the batch SMTP
processing code, which is triggered by any SMTP response that includes
a part of its SMTP command. This vulnerability is only triggered when
the 'headers_check_syntax' option is set (by default it is not set).
The bug was found by Megyer Laszlo.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains
the desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Powertools 6.2

Alpha:
exim-3.22-6x.alpha.rpm
File outdated by:  RHSA-2001:176
    95aa5201c0706cfaea1870a41d25f53b
exim-doc-3.22-6x.alpha.rpm
File outdated by:  RHSA-2001:176
    f2c3e21a38f463a0c95518e666408440
exim-mon-3.22-6x.alpha.rpm
File outdated by:  RHSA-2001:176
    6ed1390f18a2b963bb3b88b15a6094eb
 
IA-32:
exim-3.22-6x.i386.rpm
File outdated by:  RHSA-2001:176
    b4b72543e0fc06634d55c2d4349430ef
exim-doc-3.22-6x.i386.rpm
File outdated by:  RHSA-2001:176
    40085afaf670d4e11594fb115ce4ff30
exim-mon-3.22-6x.i386.rpm
File outdated by:  RHSA-2001:176
    8e7cf2dabc6ab7d33c9fa6f59d459435
 
Sparc:
exim-3.22-6x.sparc.rpm
File outdated by:  RHSA-2001:176
    add4a4813b9789d2dd9442c590e5c045
exim-doc-3.22-6x.sparc.rpm
File outdated by:  RHSA-2001:176
    0b2dcba6a11f4e7b4e67b22f4dd7e2a5
exim-mon-3.22-6x.sparc.rpm
File outdated by:  RHSA-2001:176
    6f06e75d1bf0826014ea7b559501ce82
 
Powertools 7.0

Alpha:
exim-3.22-13.7x.alpha.rpm
File outdated by:  RHSA-2001:176
    d53bd2227a99b6dd8f298a39bc2c0695
exim-doc-3.22-13.7x.alpha.rpm
File outdated by:  RHSA-2001:176
    2eee1cd59f5a5b843c22b8c06ac68b8e
exim-mon-3.22-13.7x.alpha.rpm
File outdated by:  RHSA-2001:176
    e329bcdb0d12c50026437ac4a4d561d8
 
IA-32:
exim-3.22-13.7x.i386.rpm
File outdated by:  RHSA-2001:176
    66342107a8224e887634641a72db3c0f
exim-doc-3.22-13.7x.i386.rpm
File outdated by:  RHSA-2001:176
    826a2137f61a49fce2bb6ea2083f2655
exim-mon-3.22-13.7x.i386.rpm
File outdated by:  RHSA-2001:176
    bbc30803e64269ad398a8232859364e9
 
Powertools 7.1

Alpha:
exim-3.22-14.alpha.rpm
File outdated by:  RHSA-2001:176
    00027d661e8db20db8cc21120735298e
exim-doc-3.22-14.alpha.rpm
File outdated by:  RHSA-2001:176
    712404cfc03343704f2670f5d3167a02
exim-mon-3.22-14.alpha.rpm
File outdated by:  RHSA-2001:176
    44afcb7b1e093d855ec028dc3297d7d5
 
IA-32:
exim-3.22-14.i386.rpm
File outdated by:  RHSA-2001:176
    1a6ae469f181a6957d4cf465344f2429
exim-doc-3.22-14.i386.rpm
File outdated by:  RHSA-2001:176
    c4837d8f6079f446cb032d0736e1aee6
exim-mon-3.22-14.i386.rpm
File outdated by:  RHSA-2001:176
    b476ea5bd5997c452a15281bcb5352a9
 

References


Keywords

local


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/