Updated fetchmail packages are available for Red Hat Linux 6.2, 7, 7.1,
7.2, 7.3, and 8.0 which close a remotely-exploitable vulnerability in
unpatched versions of fetchmail prior to 6.1.0.
Fetchmail is a remote mail retrieval and forwarding utility intended for
use over on-demand TCP/IP links such as SLIP and PPP connections. Two bugs
have been found in the header parsing code in versions of Fetchmail prior
to 6.1.0.
The first bug allows a remote attacker to crash Fetchmail by sending a
carefully crafted DNS packet. The second bug allows a remote attacker to
carefully craft an email in such a way that when it is parsed by Fetchmail
a heap overflow occurs, allowing remote arbitrary code execution.
Both of these bugs are only exploitable if Fetchmail is being used in
multidrop mode (using the "multiple-local-recipients" feature).
All users of Fetchmail are advised to upgrade to the errata packages
containing a backported fix which is not vulnerable to these issues.
| Red Hat Linux 6.2 |
|
| SRPMS: |
fetchmail-5.9.0-18.src.rpm
File outdated by: RHSA-2002:293 |
d7cf2f1fbaea0cb6cfa6217e17863ab8 |
| |
| Alpha: |
ftp://updates.redhat.com/6.2/en/os/alpha/fetchmail-5.9.0-18.alpha.rpm
Missing file |
e525d26cb26ccb3a18b47440f9109a7b |
ftp://updates.redhat.com/6.2/en/os/alpha/fetchmailconf-5.9.0-18.alpha.rpm
Missing file |
8991272f26c0ff7da36f7c3efbc0cfdf |
| |
| IA-32: |
fetchmail-5.9.0-18.i386.rpm
File outdated by: RHSA-2002:293 |
ea52cc0a883ac87c58cb1a8bd5bc8b5c |
fetchmailconf-5.9.0-18.i386.rpm
File outdated by: RHSA-2002:293 |
77e19ef5643b65ea1bf79724b460de86 |
| |
| Sparc: |
ftp://updates.redhat.com/6.2/en/os/sparc/fetchmail-5.9.0-18.sparc.rpm
Missing file |
eefc1f08bf8943330c3d326d34455280 |
ftp://updates.redhat.com/6.2/en/os/sparc/fetchmailconf-5.9.0-18.sparc.rpm
Missing file |
112df3d132d8008328762ff9aec031b5 |
| |
| Red Hat Linux 7.0 |
|
| SRPMS: |
fetchmail-5.9.0-19.src.rpm
File outdated by: RHSA-2002:293 |
290204c231b27011ed42530c1c941ed7 |
| |
| Alpha: |
ftp://updates.redhat.com/7.0/en/os/alpha/fetchmail-5.9.0-19.alpha.rpm
Missing file |
ebc6d8dd7596ed610ddf7dbce6676eb0 |
ftp://updates.redhat.com/7.0/en/os/alpha/fetchmailconf-5.9.0-19.alpha.rpm
Missing file |
88d6fc42260a1f60d61233273b4d7acf |
| |
| IA-32: |
fetchmail-5.9.0-19.i386.rpm
File outdated by: RHSA-2002:293 |
036a53d4e02c62eae40196ab582b57e3 |
fetchmailconf-5.9.0-19.i386.rpm
File outdated by: RHSA-2002:293 |
8e16810e7904d723e19c3fb519939eb3 |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
fetchmail-5.9.0-19.src.rpm
File outdated by: RHSA-2002:293 |
290204c231b27011ed42530c1c941ed7 |
| |
| Alpha: |
ftp://updates.redhat.com/7.1/en/os/alpha/fetchmail-5.9.0-19.alpha.rpm
Missing file |
ebc6d8dd7596ed610ddf7dbce6676eb0 |
ftp://updates.redhat.com/7.1/en/os/alpha/fetchmailconf-5.9.0-19.alpha.rpm
Missing file |
88d6fc42260a1f60d61233273b4d7acf |
| |
| IA-32: |
fetchmail-5.9.0-19.i386.rpm
File outdated by: RHSA-2002:293 |
036a53d4e02c62eae40196ab582b57e3 |
fetchmailconf-5.9.0-19.i386.rpm
File outdated by: RHSA-2002:293 |
8e16810e7904d723e19c3fb519939eb3 |
| |
| IA-64: |
ftp://updates.redhat.com/7.1/en/os/ia64/fetchmail-5.9.0-19.ia64.rpm
Missing file |
ae1c1455734a3e2bb8469ed1c8d25238 |
ftp://updates.redhat.com/7.1/en/os/ia64/fetchmailconf-5.9.0-19.ia64.rpm
Missing file |
f2997a87e0d8fa7a6e30e0d6f4c35e0b |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
fetchmail-5.9.0-20.src.rpm
File outdated by: RHSA-2002:293 |
ce79caaa93a34a1a67b6f5eb6a86efe9 |
| |
| IA-32: |
fetchmail-5.9.0-20.i386.rpm
File outdated by: RHSA-2002:293 |
7a3c7973c958b5c341598d3ec11d4667 |
fetchmailconf-5.9.0-20.i386.rpm
File outdated by: RHSA-2002:293 |
1d2f26c2c575afac0a1a594ba5579205 |
| |
| IA-64: |
fetchmail-5.9.0-20.ia64.rpm
File outdated by: RHSA-2002:293 |
b50653f90668c24b6c326bb5dc225b6d |
fetchmailconf-5.9.0-20.ia64.rpm
File outdated by: RHSA-2002:293 |
8e8c7bb8fefc064f833a1f6dc7faa79f |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
fetchmail-5.9.0-20.src.rpm
File outdated by: RHSA-2002:293 |
ce79caaa93a34a1a67b6f5eb6a86efe9 |
| |
| IA-32: |
fetchmail-5.9.0-20.i386.rpm
File outdated by: RHSA-2002:293 |
7a3c7973c958b5c341598d3ec11d4667 |
fetchmailconf-5.9.0-20.i386.rpm
File outdated by: RHSA-2002:293 |
1d2f26c2c575afac0a1a594ba5579205 |
| |
| Red Hat Linux 8.0 |
|
| SRPMS: |
fetchmail-5.9.0-21.src.rpm
File outdated by: RHSA-2002:293 |
682b5845b2fb89462eed4102e6c9a807 |
| |
| IA-32: |
fetchmail-5.9.0-21.i386.rpm
File outdated by: RHSA-2002:293 |
4c475d641dda1ed3fb553461b79d2b5c |
| |