Login
Newsletter
Werbung

Sicherheit: Fehlerhafte Erkennung von Mailanhängen in mime-tools
Aktuelle Meldungen Distributionen
Name: Fehlerhafte Erkennung von Mailanhängen in mime-tools
ID: MDKSA-2004:123
Distribution: Mandrake
Plattformen: Mandrake Corporate Server 2.1, Mandrake 9.2, Mandrake 10.0, Mandrake 10.1
Datum: Di, 2. November 2004, 12:00
Referenzen: http://lists.roaringpenguin.com/pipermail/mimedefang/2004-October/024959.html
Applikationen: perl-MIME-tools

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: perl-MIME-tools
Advisory ID: MDKSA-2004:123
Date: November 1st, 2004

Affected versions: 10.0, 10.1, 9.2, Corporate Server 2.1
______________________________________________________________________

Problem Description:

There's a bug in MIME-tools, where it mis-parses things like
boundary="". Some viruses use an empty boundary, which may allow
unapproved parts through MIMEDefang.

The updated packages are patched to fix this problem.

As well, the Updated perl-MIME-tools requires MIME::Base64 version
3.03. Since MIME::Base64 is integrated in the perl package on
Mandakelinux, these updates now provide the newer version.
_______________________________________________________________________

References:

http://lists.roaringpenguin.com/pipermail/mimedefang/2004-October/024959.html
______________________________________________________________________

Updated Packages:

Mandrakelinux 10.0:
d278882284c3883d1cfa31940d7da937 10.0/RPMS/perl-5.8.3-5.1.100mdk.i586.rpm
2769a4030ba0ab283e976559c75a6b90
10.0/RPMS/perl-base-5.8.3-5.1.100mdk.i586.rpm
c5ba0bbe1251056c88a2148208c01314
10.0/RPMS/perl-devel-5.8.3-5.1.100mdk.i586.rpm
3d0f1a43934ec2845d09693956931572 10.0/RPMS/perl-doc-5.8.3-5.1.100mdk.i586.rpm
0fb9ebc38b5e217dc652428d15da9094
10.0/RPMS/perl-MIME-tools-5.415-1.0.100mdk.noarch.rpm
71339cbf22986868ef9397e23a0773b0 10.0/SRPMS/perl-5.8.3-5.1.100mdk.src.rpm
447551691963d906919f92a80ba5f4d7
10.0/SRPMS/perl-MIME-tools-5.415-1.0.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
10a20606840674bfd2ffe7b6c6f1707b
amd64/10.0/RPMS/perl-5.8.3-5.1.100mdk.amd64.rpm
560e79ba8cea968ca06f504bd74be04b
amd64/10.0/RPMS/perl-base-5.8.3-5.1.100mdk.amd64.rpm
7f9d8d26bbe8b72b485356c20053590d
amd64/10.0/RPMS/perl-devel-5.8.3-5.1.100mdk.amd64.rpm
d40dea320e9441854af7059e86f9e4da
amd64/10.0/RPMS/perl-doc-5.8.3-5.1.100mdk.amd64.rpm
e2136dddff55d5a48b04247997bf599f
amd64/10.0/RPMS/perl-MIME-tools-5.415-1.0.100mdk.noarch.rpm
71339cbf22986868ef9397e23a0773b0
amd64/10.0/SRPMS/perl-5.8.3-5.1.100mdk.src.rpm
447551691963d906919f92a80ba5f4d7
amd64/10.0/SRPMS/perl-MIME-tools-5.415-1.0.100mdk.src.rpm

Mandrakelinux 10.1:
4ee65c401fcb1f7e9e445dfae0cde9b9 10.1/RPMS/perl-5.8.5-3.1.101mdk.i586.rpm
de5f7cb7a5d9d7059779582761d98318
10.1/RPMS/perl-base-5.8.5-3.1.101mdk.i586.rpm
27b69c2804d9531d4eb4dbed31813732
10.1/RPMS/perl-devel-5.8.5-3.1.101mdk.i586.rpm
26dbf1cb9d0ffd6d7a402c07aa749251 10.1/RPMS/perl-doc-5.8.5-3.1.101mdk.i586.rpm
1fbeed384ad6c39ca80de7dee2b62400
10.1/RPMS/perl-MIME-tools-5.415-1.0.101mdk.noarch.rpm
a900cfda5596a33ee321ed270837b0e0 10.1/SRPMS/perl-5.8.5-3.1.101mdk.src.rpm
33b061fe528a62a9bb5315cd37ba55e8
10.1/SRPMS/perl-MIME-tools-5.415-1.0.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:
f75cb59f2c0658a2cbe5357a09d8d07d
x86_64/10.1/RPMS/perl-5.8.5-3.1.101mdk.x86_64.rpm
802509f65ba952bd07325bd6f2b0d3a0
x86_64/10.1/RPMS/perl-base-5.8.5-3.1.101mdk.x86_64.rpm
9325c49c6f77d90483437f6f47e55b9d
x86_64/10.1/RPMS/perl-devel-5.8.5-3.1.101mdk.x86_64.rpm
d484a0e660829aa32a302138db94f66e
x86_64/10.1/RPMS/perl-doc-5.8.5-3.1.101mdk.x86_64.rpm
b13178dab9710e61910a4af762e7d6a3
x86_64/10.1/RPMS/perl-MIME-tools-5.415-1.0.101mdk.noarch.rpm
a900cfda5596a33ee321ed270837b0e0
x86_64/10.1/SRPMS/perl-5.8.5-3.1.101mdk.src.rpm
33b061fe528a62a9bb5315cd37ba55e8
x86_64/10.1/SRPMS/perl-MIME-tools-5.415-1.0.101mdk.src.rpm

Corporate Server 2.1:
fc3e3f06637d571a281e639aa4490e76
corporate/2.1/RPMS/perl-5.8.0-14.2.C21mdk.i586.rpm
e039f009751fad2b77d160b67ca75218
corporate/2.1/RPMS/perl-base-5.8.0-14.2.C21mdk.i586.rpm
cceb9017b7c5d62a6846f24931c0d777
corporate/2.1/RPMS/perl-devel-5.8.0-14.2.C21mdk.i586.rpm
fb9beebfa93a3eebc86bb9012cdff1c4
corporate/2.1/RPMS/perl-doc-5.8.0-14.2.C21mdk.i586.rpm
9b484ca12bfdda17787f94d5da96613d
corporate/2.1/RPMS/perl-MIME-tools-5.415-1.0.C21mdk.noarch.rpm
19dc7a7ac3e12a653901c5119315d10f
corporate/2.1/SRPMS/perl-5.8.0-14.2.C21mdk.src.rpm
5987507b55b00b66ec461c0bdf994ee1
corporate/2.1/SRPMS/perl-MIME-tools-5.415-1.0.C21mdk.src.rpm

Corporate Server 2.1/x86_64:
f9d3fbf772cb558c945abe442b1e99be
x86_64/corporate/2.1/RPMS/perl-5.8.0-14.2.C21mdk.x86_64.rpm
32731b18b86678988d56b63342bb8c32
x86_64/corporate/2.1/RPMS/perl-base-5.8.0-14.2.C21mdk.x86_64.rpm
c54830d6c0beac9699d36c875a91a4ae
x86_64/corporate/2.1/RPMS/perl-devel-5.8.0-14.2.C21mdk.x86_64.rpm
595fcf030bbebf23a2be36fc36fc7dde
x86_64/corporate/2.1/RPMS/perl-doc-5.8.0-14.2.C21mdk.x86_64.rpm
e31b6cfb93edab14b43076d4e9596c4c
x86_64/corporate/2.1/RPMS/perl-MIME-tools-5.415-1.0.C21mdk.noarch.rpm
19dc7a7ac3e12a653901c5119315d10f
x86_64/corporate/2.1/SRPMS/perl-5.8.0-14.2.C21mdk.src.rpm
5987507b55b00b66ec461c0bdf994ee1
x86_64/corporate/2.1/SRPMS/perl-MIME-tools-5.415-1.0.C21mdk.src.rpm

Mandrakelinux 9.2:
4e0dda0496ac2227496a10301d148add 9.2/RPMS/perl-5.8.1-0.RC4.3.1.92mdk.i586.rpm
44fb5ff7b4478e81d726c7f74883dcdf
9.2/RPMS/perl-base-5.8.1-0.RC4.3.1.92mdk.i586.rpm
b0c3828bd61669878065117e34283104
9.2/RPMS/perl-devel-5.8.1-0.RC4.3.1.92mdk.i586.rpm
fe0b5b68eb8fabf63a56d132da860c5c
9.2/RPMS/perl-doc-5.8.1-0.RC4.3.1.92mdk.i586.rpm
b7a8db45f13d78babcf7dbb28fd1c3b9
9.2/RPMS/perl-MIME-tools-5.415-1.0.92mdk.noarch.rpm
4979228b456acf79ea08749c63dd8c12 9.2/SRPMS/perl-5.8.1-0.RC4.3.1.92mdk.src.rpm
a2cb97e745ebf53551b18f771664b9e5
9.2/SRPMS/perl-MIME-tools-5.415-1.0.92mdk.src.rpm

Mandrakelinux 9.2/AMD64:
7f2ce1931161337b3b910a73df00d269
amd64/9.2/RPMS/perl-5.8.1-0.RC4.3.1.92mdk.amd64.rpm
e79be61ff5029e04c5a7953ad87edcd6
amd64/9.2/RPMS/perl-base-5.8.1-0.RC4.3.1.92mdk.amd64.rpm
cf1c03ee01613bc2f787963345966072
amd64/9.2/RPMS/perl-devel-5.8.1-0.RC4.3.1.92mdk.amd64.rpm
1c6c7de92d04bd820edd19eeb15ad999
amd64/9.2/RPMS/perl-doc-5.8.1-0.RC4.3.1.92mdk.amd64.rpm
8f92a60447dcb0fc66d548ca3a667648
amd64/9.2/RPMS/perl-MIME-tools-5.415-1.0.92mdk.noarch.rpm
4979228b456acf79ea08749c63dd8c12
amd64/9.2/SRPMS/perl-5.8.1-0.RC4.3.1.92mdk.src.rpm
a2cb97e745ebf53551b18f771664b9e5
amd64/9.2/SRPMS/perl-MIME-tools-5.415-1.0.92mdk.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandrakesoft for security. You can obtain
the GPG public key of the Mandrakelinux Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandrakelinux at:

http://www.mandrakesoft.com/security/advisories

If you want to report vulnerabilities, please contact

security_linux-mandrake.com

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Linux Mandrake Security Team
<security linux-mandrake.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQFBhtgNmqjQ0CJFipgRAlPVAKCfqgd5M8dTJvpeikgISKCPME9MAgCfdPkk
t28kCv9HUY+FFQR2xudQr74=
=AtvC
-----END PGP SIGNATURE-----


____________________________________________________
Want to buy your Pack or Services from MandrakeSoft?
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung