Security Advisory Updated Fetchmail packages fix security vulnerabilities

Advisory: RHSA-2003:155-04
Type: Security Advisory
Severity: N/A
Issued on: 2003-04-24
Last updated on: 2003-04-24
Affected Products: Red Hat Linux 7.1 for iSeries
Red Hat Linux 7.1 for pSeries
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-1174
CVE-2002-1175
CVE-2002-1365

Details

Updated Fetchmail packages that close a number of vulnerabilities are
available for Red Hat Linux on IBM iSeries and pSeries systems.

Fetchmail is a remote mail retrieval and forwarding utility intended for
use over on-demand TCP/IP links such as SLIP and PPP connections. Three
bugs have been found in the header parsing code in Fetchmail versions
prior to 6.2.0:

A heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not
account for the "@" character when determining buffer lengths for local
addresses, which allows remote attackers to execute arbitrary code via a
header with a large number of local addresses.

Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to
cause a denial of service (crash) or execute arbitrary code via long
headers that are not properly processed by the readheaders function, or
via long Received: headers, which are not properly parsed by the
parse_received function.

The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly
check the boundary of a particular malformed DNS packet from a malicious
DNS server, which allows remote attackers to cause a denial of service
(crash) when Fetchmail attempts to read data beyond the expected boundary.

All users of Fetchmail are advised to upgrade to the errata packages
containing a backported fix, which is not vulnerable to these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.1 for iSeries

SRPMS:
ftp://updates.redhat.com/7.1/en/os/iSeries/SRPMS/fetchmail-5.9.0-21.7.1.src.rpm
Missing file
    9b976c0c149a670b871cc776f8157753
 
iSeries:
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/fetchmail-5.9.0-21.7.1.ppc.rpm
Missing file
    4949262ac200e0089c442a22d26524bb
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/fetchmailconf-5.9.0-21.7.1.ppc.rpm
Missing file
    e490a418efafeef66a4215e7cff8e613
 
Red Hat Linux 7.1 for pSeries

SRPMS:
ftp://updates.redhat.com/7.1/en/os/pSeries/SRPMS/fetchmail-5.9.0-21.7.1.src.rpm
Missing file
    9b976c0c149a670b871cc776f8157753
 
pSeries:
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/fetchmail-5.9.0-21.7.1.ppc.rpm
Missing file
    4949262ac200e0089c442a22d26524bb
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/fetchmailconf-5.9.0-21.7.1.ppc.rpm
Missing file
    e490a418efafeef66a4215e7cff8e613
 

References


Keywords

fetchmail, multidrop, remote


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/