Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Fetchmail
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Fetchmail
ID: MDVSA-2011:107
Distribution: Mandriva
Plattformen: Mandriva Corporate 4.0, Mandriva 2009.0, Mandriva Enterprise Server 5.0, Mandriva 2010.1
Datum: Di, 7. Juni 2011, 14:07
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1167
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1947
http://seclists.org/oss-sec/2011/q2/551
Applikationen: Fetchmail

Originalnachricht

This is a multi-part message in MIME format...

------------=_1307447112-2461-160

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2011:107
http://www.mandriva.com/security/
_______________________________________________________________________

Package : fetchmail
Date : June 7, 2011
Affected: 2009.0, 2010.1, Corporate 4.0, Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities were discovered and corrected in fetchmail:

fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does
not properly handle invalid characters in a multi-character locale,
which allows remote attackers to cause a denial of service (memory
consumption and application crash) via a crafted (1) message header or
(2) POP3 UIDL list (CVE-2010-1167). NOTE: This vulnerability did not
affect Mandriva Linux 2010.2.

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait
time after issuing a (1) STARTTLS or (2) STLS request, which allows
remote servers to cause a denial of service (application hang)
by acknowledging the request but not sending additional packets
(CVE-2011-1947).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

The updated packages have been upgraded to the 6.3.20 version which
is not vulnerable to these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1167
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1947
http://seclists.org/oss-sec/2011/q2/551
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2009.0:
fa463380143ddd8b37d761fa02bdcd4d
2009.0/i586/fetchmail-6.3.20-0.1mdv2009.0.i586.rpm
33c88d95440a52ff3baa229b132f9cc7
2009.0/i586/fetchmailconf-6.3.20-0.1mdv2009.0.i586.rpm
a07c07a7ed25d8ece92eb2bba3cb8052
2009.0/i586/fetchmail-daemon-6.3.20-0.1mdv2009.0.i586.rpm
d06dc796666631cc2c33470366413380
2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
d068668a5be3b422ac49ee68376ef2f2
2009.0/x86_64/fetchmail-6.3.20-0.1mdv2009.0.x86_64.rpm
5d586cf7cbaa5a661bef2b79a32f9841
2009.0/x86_64/fetchmailconf-6.3.20-0.1mdv2009.0.x86_64.rpm
3d6f73e1b46c7b154b4ade245498642b
2009.0/x86_64/fetchmail-daemon-6.3.20-0.1mdv2009.0.x86_64.rpm
d06dc796666631cc2c33470366413380
2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

Mandriva Linux 2010.1:
4e1f0cf13ad4dd13de33e598b54ed10c
2010.1/i586/fetchmail-6.3.20-0.1mdv2010.2.i586.rpm
9d99d5360bacbee18a354b40d73dbdce
2010.1/i586/fetchmailconf-6.3.20-0.1mdv2010.2.i586.rpm
00595fe4b19c6de7a788a2669ca27c1e
2010.1/i586/fetchmail-daemon-6.3.20-0.1mdv2010.2.i586.rpm
580622099149b837d73746ea58d6e401
2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

Mandriva Linux 2010.1/X86_64:
727d0e55ff5c10a6d61642be1ba243ec
2010.1/x86_64/fetchmail-6.3.20-0.1mdv2010.2.x86_64.rpm
dc672cd266a8e8267170e790f797a706
2010.1/x86_64/fetchmailconf-6.3.20-0.1mdv2010.2.x86_64.rpm
04284804437e9d6b0ac3cf451483a52e
2010.1/x86_64/fetchmail-daemon-6.3.20-0.1mdv2010.2.x86_64.rpm
580622099149b837d73746ea58d6e401
2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

Corporate 4.0:
835fbe8cccecac21c87856a74fc630e1
corporate/4.0/i586/fetchmail-6.3.20-0.1.20060mlcs4.i586.rpm
98246f052294392137bf7c796a9e27f9
corporate/4.0/i586/fetchmailconf-6.3.20-0.1.20060mlcs4.i586.rpm
f678d210a8d3784c661a7ff53cf70d90
corporate/4.0/i586/fetchmail-daemon-6.3.20-0.1.20060mlcs4.i586.rpm
33abcf7dea9f25d8a752cbb93f0f436f
corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
2da71f289543859e9665988dcc36e12b
corporate/4.0/x86_64/fetchmail-6.3.20-0.1.20060mlcs4.x86_64.rpm
44bf90966c95ccaf70eebadd8c774463
corporate/4.0/x86_64/fetchmailconf-6.3.20-0.1.20060mlcs4.x86_64.rpm
83c9e6d7b456a195197cba0834fa1a4b
corporate/4.0/x86_64/fetchmail-daemon-6.3.20-0.1.20060mlcs4.x86_64.rpm
33abcf7dea9f25d8a752cbb93f0f436f
corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

Mandriva Enterprise Server 5:
9978d5caa0f8b529ca65f372318e7def
mes5/i586/fetchmail-6.3.20-0.1mdvmes5.2.i586.rpm
4e6d7445d7fe568dc8318a8307a032d9
mes5/i586/fetchmailconf-6.3.20-0.1mdvmes5.2.i586.rpm
82e050b23068208becda3b2efe691626
mes5/i586/fetchmail-daemon-6.3.20-0.1mdvmes5.2.i586.rpm
0abdef167f8d00f6980bda48940df1ce
mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
4923eef5e0f29e72a407b4806c890008
mes5/x86_64/fetchmail-6.3.20-0.1mdvmes5.2.x86_64.rpm
19d714a319a0d7e0a823c9bb1f6a6ccf
mes5/x86_64/fetchmailconf-6.3.20-0.1mdvmes5.2.x86_64.rpm
4c99cfa954f822bd413ae3e8a8ca6d7e
mes5/x86_64/fetchmail-daemon-6.3.20-0.1mdvmes5.2.x86_64.rpm
0abdef167f8d00f6980bda48940df1ce
mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFN7d5nmqjQ0CJFipgRAtLLAJ9VSpRLSdD8QGsKncFboVQN8CO2igCdGP8x
PzDnbLgLQyU76ed0DYpozro=
=nIBN
-----END PGP SIGNATURE-----


------------=_1307447112-2461-160
Content-Type: text/plain; charset="UTF-8";
name="message-footer.txt"
Content-Disposition: inline; filename="message-footer.txt"
Content-Transfer-Encoding: 8bit

To unsubscribe, send a email to sympa@mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://www.mandrivastore.com
Join the Club : http://www.mandrivaclub.com
_______________________________________________________

------------=_1307447112-2461-160--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung