lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <E1QTufY-0007uq-LC@titan.mandriva.com>
Date: Tue, 07 Jun 2011 13:42:00 +0200
From: security@...driva.com
To: bugtraq@...urityfocus.com
Subject: [ MDVSA-2011:107 ] fetchmail

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2011:107
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : fetchmail
 Date    : June 7, 2011
 Affected: 2009.0, 2010.1, Corporate 4.0, Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

 Multiple vulnerabilities were discovered and corrected in fetchmail:
 
 fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does
 not properly handle invalid characters in a multi-character locale,
 which allows remote attackers to cause a denial of service (memory
 consumption and application crash) via a crafted (1) message header or
 (2) POP3 UIDL list (CVE-2010-1167). NOTE: This vulnerability did not
 affect Mandriva Linux 2010.2.
 
 fetchmail 5.9.9 through 6.3.19 does not properly limit the wait
 time after issuing a (1) STARTTLS or (2) STLS request, which allows
 remote servers to cause a denial of service (application hang)
 by acknowledging the request but not sending additional packets
 (CVE-2011-1947).
 
 Packages for 2009.0 are provided as of the Extended Maintenance
 Program. Please visit this link to learn more:
 http://store.mandriva.com/product_info.php?cPath=149&amp;products_id=490
 
 The updated packages have been upgraded to the 6.3.20 version which
 is not vulnerable to these issues.
 _______________________________________________________________________

 References:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1167
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1947
 http://seclists.org/oss-sec/2011/q2/551
 _______________________________________________________________________

 Updated Packages:

 Mandriva Linux 2009.0:
 fa463380143ddd8b37d761fa02bdcd4d  2009.0/i586/fetchmail-6.3.20-0.1mdv2009.0.i586.rpm
 33c88d95440a52ff3baa229b132f9cc7  2009.0/i586/fetchmailconf-6.3.20-0.1mdv2009.0.i586.rpm
 a07c07a7ed25d8ece92eb2bba3cb8052  2009.0/i586/fetchmail-daemon-6.3.20-0.1mdv2009.0.i586.rpm 
 d06dc796666631cc2c33470366413380  2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

 Mandriva Linux 2009.0/X86_64:
 d068668a5be3b422ac49ee68376ef2f2  2009.0/x86_64/fetchmail-6.3.20-0.1mdv2009.0.x86_64.rpm
 5d586cf7cbaa5a661bef2b79a32f9841  2009.0/x86_64/fetchmailconf-6.3.20-0.1mdv2009.0.x86_64.rpm
 3d6f73e1b46c7b154b4ade245498642b  2009.0/x86_64/fetchmail-daemon-6.3.20-0.1mdv2009.0.x86_64.rpm 
 d06dc796666631cc2c33470366413380  2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

 Mandriva Linux 2010.1:
 4e1f0cf13ad4dd13de33e598b54ed10c  2010.1/i586/fetchmail-6.3.20-0.1mdv2010.2.i586.rpm
 9d99d5360bacbee18a354b40d73dbdce  2010.1/i586/fetchmailconf-6.3.20-0.1mdv2010.2.i586.rpm
 00595fe4b19c6de7a788a2669ca27c1e  2010.1/i586/fetchmail-daemon-6.3.20-0.1mdv2010.2.i586.rpm 
 580622099149b837d73746ea58d6e401  2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

 Mandriva Linux 2010.1/X86_64:
 727d0e55ff5c10a6d61642be1ba243ec  2010.1/x86_64/fetchmail-6.3.20-0.1mdv2010.2.x86_64.rpm
 dc672cd266a8e8267170e790f797a706  2010.1/x86_64/fetchmailconf-6.3.20-0.1mdv2010.2.x86_64.rpm
 04284804437e9d6b0ac3cf451483a52e  2010.1/x86_64/fetchmail-daemon-6.3.20-0.1mdv2010.2.x86_64.rpm 
 580622099149b837d73746ea58d6e401  2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

 Corporate 4.0:
 835fbe8cccecac21c87856a74fc630e1  corporate/4.0/i586/fetchmail-6.3.20-0.1.20060mlcs4.i586.rpm
 98246f052294392137bf7c796a9e27f9  corporate/4.0/i586/fetchmailconf-6.3.20-0.1.20060mlcs4.i586.rpm
 f678d210a8d3784c661a7ff53cf70d90  corporate/4.0/i586/fetchmail-daemon-6.3.20-0.1.20060mlcs4.i586.rpm 
 33abcf7dea9f25d8a752cbb93f0f436f  corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

 Corporate 4.0/X86_64:
 2da71f289543859e9665988dcc36e12b  corporate/4.0/x86_64/fetchmail-6.3.20-0.1.20060mlcs4.x86_64.rpm
 44bf90966c95ccaf70eebadd8c774463  corporate/4.0/x86_64/fetchmailconf-6.3.20-0.1.20060mlcs4.x86_64.rpm
 83c9e6d7b456a195197cba0834fa1a4b  corporate/4.0/x86_64/fetchmail-daemon-6.3.20-0.1.20060mlcs4.x86_64.rpm 
 33abcf7dea9f25d8a752cbb93f0f436f  corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

 Mandriva Enterprise Server 5:
 9978d5caa0f8b529ca65f372318e7def  mes5/i586/fetchmail-6.3.20-0.1mdvmes5.2.i586.rpm
 4e6d7445d7fe568dc8318a8307a032d9  mes5/i586/fetchmailconf-6.3.20-0.1mdvmes5.2.i586.rpm
 82e050b23068208becda3b2efe691626  mes5/i586/fetchmail-daemon-6.3.20-0.1mdvmes5.2.i586.rpm 
 0abdef167f8d00f6980bda48940df1ce  mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm

 Mandriva Enterprise Server 5/X86_64:
 4923eef5e0f29e72a407b4806c890008  mes5/x86_64/fetchmail-6.3.20-0.1mdvmes5.2.x86_64.rpm
 19d714a319a0d7e0a823c9bb1f6a6ccf  mes5/x86_64/fetchmailconf-6.3.20-0.1mdvmes5.2.x86_64.rpm
 4c99cfa954f822bd413ae3e8a8ca6d7e  mes5/x86_64/fetchmail-daemon-6.3.20-0.1mdvmes5.2.x86_64.rpm 
 0abdef167f8d00f6980bda48940df1ce  mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandriva Linux at:

  http://www.mandriva.com/security/advisories

 If you want to report vulnerabilities, please contact

  security_(at)_mandriva.com
 _______________________________________________________________________

 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFN7d5nmqjQ0CJFipgRAtLLAJ9VSpRLSdD8QGsKncFboVQN8CO2igCdGP8x
PzDnbLgLQyU76ed0DYpozro=
=nIBN
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ