Updated libc-client packages that fix a buffer overflow issue are now
available.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
C-client is a common API for accessing mailboxes.
A buffer overflow flaw was discovered in the way C-client parses user
supplied mailboxes. If an authenticated user requests a specially crafted
mailbox name, it may be possible to execute arbitrary code on a server that
uses C-client to access mailboxes. The Common Vulnerabilities and Exposures
project has assigned the name CVE-2005-2933 to this issue.
All users of libc-client should upgrade to these updated packages, which
contain a backported patch that resolves this issue.
| Red Hat Desktop (v. 4) |
|
| SRPMS: |
| libc-client-2002e-14.src.rpm |
e050f3b294c3a810f9c62a5a4ad8ee35 |
| |
| IA-32: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-devel-2002e-14.i386.rpm |
15a992bb5fd6a334e430626d194efb83 |
| |
| x86_64: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-2002e-14.x86_64.rpm |
37898475b279206da3375d5f4d95b91e |
| libc-client-devel-2002e-14.x86_64.rpm |
678b838f2f0e13af8343ccac76c0b82a |
| |
| Red Hat Enterprise Linux AS (v. 4) |
|
| SRPMS: |
| libc-client-2002e-14.src.rpm |
e050f3b294c3a810f9c62a5a4ad8ee35 |
| |
| IA-32: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-devel-2002e-14.i386.rpm |
15a992bb5fd6a334e430626d194efb83 |
| |
| IA-64: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-2002e-14.ia64.rpm |
d82f92b0aa198d5c57a74f849b6233db |
| libc-client-devel-2002e-14.ia64.rpm |
e997fd97ca8970294bb50378ff86de69 |
| |
| PPC: |
| libc-client-2002e-14.ppc.rpm |
895819bc9ab63446494b0771da35da91 |
| libc-client-2002e-14.ppc64.rpm |
075bae7362a94821ef9b329eca9ab239 |
| libc-client-devel-2002e-14.ppc.rpm |
7a7af03991228dd6e8904f7e6ae152bf |
| |
| s390: |
| libc-client-2002e-14.s390.rpm |
782730a8a1ad886fd69ad0918369e5d7 |
| libc-client-devel-2002e-14.s390.rpm |
bd98ece7dc7ad68aa1e2d5d54f2c7a30 |
| |
| s390x: |
| libc-client-2002e-14.s390.rpm |
782730a8a1ad886fd69ad0918369e5d7 |
| libc-client-2002e-14.s390x.rpm |
bede6046b6b14dc2e7e3fe7a7a3c35df |
| libc-client-devel-2002e-14.s390x.rpm |
4662ba7a95544c1860fce45152ceb659 |
| |
| x86_64: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-2002e-14.x86_64.rpm |
37898475b279206da3375d5f4d95b91e |
| libc-client-devel-2002e-14.x86_64.rpm |
678b838f2f0e13af8343ccac76c0b82a |
| |
| Red Hat Enterprise Linux ES (v. 4) |
|
| SRPMS: |
| libc-client-2002e-14.src.rpm |
e050f3b294c3a810f9c62a5a4ad8ee35 |
| |
| IA-32: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-devel-2002e-14.i386.rpm |
15a992bb5fd6a334e430626d194efb83 |
| |
| IA-64: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-2002e-14.ia64.rpm |
d82f92b0aa198d5c57a74f849b6233db |
| libc-client-devel-2002e-14.ia64.rpm |
e997fd97ca8970294bb50378ff86de69 |
| |
| x86_64: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-2002e-14.x86_64.rpm |
37898475b279206da3375d5f4d95b91e |
| libc-client-devel-2002e-14.x86_64.rpm |
678b838f2f0e13af8343ccac76c0b82a |
| |
| Red Hat Enterprise Linux WS (v. 4) |
|
| SRPMS: |
| libc-client-2002e-14.src.rpm |
e050f3b294c3a810f9c62a5a4ad8ee35 |
| |
| IA-32: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-devel-2002e-14.i386.rpm |
15a992bb5fd6a334e430626d194efb83 |
| |
| IA-64: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-2002e-14.ia64.rpm |
d82f92b0aa198d5c57a74f849b6233db |
| libc-client-devel-2002e-14.ia64.rpm |
e997fd97ca8970294bb50378ff86de69 |
| |
| x86_64: |
| libc-client-2002e-14.i386.rpm |
c6460f746fa52858d1e617e5aa5f8791 |
| libc-client-2002e-14.x86_64.rpm |
37898475b279206da3375d5f4d95b91e |
| libc-client-devel-2002e-14.x86_64.rpm |
678b838f2f0e13af8343ccac76c0b82a |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
171344 - CVE-2005-2933 imap buffer overflow