Skip to navigation

Security Advisory fetchmail security update

Advisory: RHSA-2002:216-13
Type: Security Advisory
Severity: Critical
Issued on: 2002-09-30
Last updated on: 2002-10-07
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
CVEs (cve.mitre.org): CVE-2002-1174
CVE-2002-1175

Details

Updated Fetchmail packages are available for Red Hat Linux Advanced Server
which close a remotely-exploitable vulnerability in unpatched versions of
Fetchmail prior to 6.1.0.

Fetchmail is a remote mail retrieval and forwarding utility intended for
use over on-demand TCP/IP links such as SLIP and PPP connections. Two bugs
have been found in the header parsing code in versions of Fetchmail prior
to 6.1.0.

The first bug allows a remote attacker to crash Fetchmail by sending a
carefully crafted DNS packet. The second bug allows a remote attacker to
carefully craft an email in such a way that when it is parsed by Fetchmail
a heap overflow occurs, allowing remote arbitrary code execution.

Both of these bugs are only exploitable if Fetchmail is being used in
multidrop mode (using the "multiple-local-recipients" feature).

All users of Fetchmail are advised to upgrade to the errata packages
containing a backported fix which is not vulnerable to these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
fetchmail-5.9.0-20.src.rpm
File outdated by:  RHSA-2007:0385
    MD5: ce79caaa93a34a1a67b6f5eb6a86efe9
 
IA-32:
fetchmail-5.9.0-20.i386.rpm
File outdated by:  RHSA-2007:0385
    MD5: 7a3c7973c958b5c341598d3ec11d4667
fetchmailconf-5.9.0-20.i386.rpm
File outdated by:  RHSA-2007:0385
    MD5: 1d2f26c2c575afac0a1a594ba5579205
 

Bugs fixed (see bugzilla for more information)

74664 - Fetchmail multidrop remote security vulnerabilities


References


Keywords

fetchmail, multidrop, remote


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/