fetchmail security update
| Advisory: | RHSA-2002:216-13 |
|---|---|
| Type: | Security Advisory |
| Severity: | Critical |
| Issued on: | 2002-09-30 |
| Last updated on: | 2002-10-07 |
| Affected Products: | Red Hat Enterprise Linux AS (v. 2.1) |
| CVEs (cve.mitre.org): |
CVE-2002-1174 CVE-2002-1175 |
Details
Updated Fetchmail packages are available for Red Hat Linux Advanced Server
which close a remotely-exploitable vulnerability in unpatched versions of
Fetchmail prior to 6.1.0.
Fetchmail is a remote mail retrieval and forwarding utility intended for
use over on-demand TCP/IP links such as SLIP and PPP connections. Two bugs
have been found in the header parsing code in versions of Fetchmail prior
to 6.1.0.
The first bug allows a remote attacker to crash Fetchmail by sending a
carefully crafted DNS packet. The second bug allows a remote attacker to
carefully craft an email in such a way that when it is parsed by Fetchmail
a heap overflow occurs, allowing remote arbitrary code execution.
Both of these bugs are only exploitable if Fetchmail is being used in
multidrop mode (using the "multiple-local-recipients" feature).
All users of Fetchmail are advised to upgrade to the errata packages
containing a backported fix which is not vulnerable to these issues.
Solution
relevant to your system have been applied.
This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Updated packages
| Red Hat Enterprise Linux AS (v. 2.1) | |
| SRPMS: | |
| fetchmail-5.9.0-20.src.rpm File outdated by: RHSA-2007:0385 |
MD5: ce79caaa93a34a1a67b6f5eb6a86efe9 |
| IA-32: | |
| fetchmail-5.9.0-20.i386.rpm File outdated by: RHSA-2007:0385 |
MD5: 7a3c7973c958b5c341598d3ec11d4667 |
| fetchmailconf-5.9.0-20.i386.rpm File outdated by: RHSA-2007:0385 |
MD5: 1d2f26c2c575afac0a1a594ba5579205 |
Bugs fixed (see bugzilla for more information)
74664 - Fetchmail multidrop remote security vulnerabilities
References
https://www.redhat.com/security/data/cve/CVE-2002-1175.html
http://tuxedo.org/~esr/fetchmail/NEWS
http://security.e-matters.de/advisories/032002.html
http://www.kb.cert.org/vuls/id/738331
Keywords
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/