BugTraq
[ MDVSA-2011:107 ] fetchmail Jun 07 2011 11:42AM
security mandriva com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2011:107
http://www.mandriva.com/security/
_______________________________________________________________________

Package : fetchmail
Date : June 7, 2011
Affected: 2009.0, 2010.1, Corporate 4.0, Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities were discovered and corrected in fetchmail:

fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does
not properly handle invalid characters in a multi-character locale,
which allows remote attackers to cause a denial of service (memory
consumption and application crash) via a crafted (1) message header or
(2) POP3 UIDL list (CVE-2010-1167). NOTE: This vulnerability did not
affect Mandriva Linux 2010.2.

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait
time after issuing a (1) STARTTLS or (2) STLS request, which allows
remote servers to cause a denial of service (application hang)
by acknowledging the request but not sending additional packets
(CVE-2011-1947).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

The updated packages have been upgraded to the 6.3.20 version which
is not vulnerable to these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1167
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1947
http://seclists.org/oss-sec/2011/q2/551
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2009.0:
fa463380143ddd8b37d761fa02bdcd4d 2009.0/i586/fetchmail-6.3.20-0.1mdv2009.0.i586.rpm
33c88d95440a52ff3baa229b132f9cc7 2009.0/i586/fetchmailconf-6.3.20-0.1mdv2009.0.i586.rpm
a07c07a7ed25d8ece92eb2bba3cb8052 2009.0/i586/fetchmail-daemon-6.3.20-0.1mdv2009.0.i586.rpm
d06dc796666631cc2c33470366413380 2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
d068668a5be3b422ac49ee68376ef2f2 2009.0/x86_64/fetchmail-6.3.20-0.1mdv2009.0.x86_64.rpm
5d586cf7cbaa5a661bef2b79a32f9841 2009.0/x86_64/fetchmailconf-6.3.20-0.1mdv2009.0.x86_64.rpm
3d6f73e1b46c7b154b4ade245498642b 2009.0/x86_64/fetchmail-daemon-6.3.20-0.1mdv2009.0.x86_64.rpm
d06dc796666631cc2c33470366413380 2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

Mandriva Linux 2010.1:
4e1f0cf13ad4dd13de33e598b54ed10c 2010.1/i586/fetchmail-6.3.20-0.1mdv2010.2.i586.rpm
9d99d5360bacbee18a354b40d73dbdce 2010.1/i586/fetchmailconf-6.3.20-0.1mdv2010.2.i586.rpm
00595fe4b19c6de7a788a2669ca27c1e 2010.1/i586/fetchmail-daemon-6.3.20-0.1mdv2010.2.i586.rpm
580622099149b837d73746ea58d6e401 2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

Mandriva Linux 2010.1/X86_64:
727d0e55ff5c10a6d61642be1ba243ec 2010.1/x86_64/fetchmail-6.3.20-0.1mdv2010.2.x86_64.rpm
dc672cd266a8e8267170e790f797a706 2010.1/x86_64/fetchmailconf-6.3.20-0.1mdv2010.2.x86_64.rpm
04284804437e9d6b0ac3cf451483a52e 2010.1/x86_64/fetchmail-daemon-6.3.20-0.1mdv2010.2.x86_64.rpm
580622099149b837d73746ea58d6e401 2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

Corporate 4.0:
835fbe8cccecac21c87856a74fc630e1 corporate/4.0/i586/fetchmail-6.3.20-0.1.20060mlcs4.i586.rpm
98246f052294392137bf7c796a9e27f9 corporate/4.0/i586/fetchmailconf-6.3.20-0.1.20060mlcs4.i586.rpm
f678d210a8d3784c661a7ff53cf70d90 corporate/4.0/i586/fetchmail-daemon-6.3.20-0.1.20060mlcs4.i586.rpm
33abcf7dea9f25d8a752cbb93f0f436f corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
2da71f289543859e9665988dcc36e12b corporate/4.0/x86_64/fetchmail-6.3.20-0.1.20060mlcs4.x86_64.rpm
44bf90966c95ccaf70eebadd8c774463 corporate/4.0/x86_64/fetchmailconf-6.3.20-0.1.20060mlcs4.x86_64.rpm
83c9e6d7b456a195197cba0834fa1a4b corporate/4.0/x86_64/fetchmail-daemon-6.3.20-0.1.20060mlcs4.x86_64.rpm
33abcf7dea9f25d8a752cbb93f0f436f corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

Mandriva Enterprise Server 5:
9978d5caa0f8b529ca65f372318e7def mes5/i586/fetchmail-6.3.20-0.1mdvmes5.2.i586.rpm
4e6d7445d7fe568dc8318a8307a032d9 mes5/i586/fetchmailconf-6.3.20-0.1mdvmes5.2.i586.rpm
82e050b23068208becda3b2efe691626 mes5/i586/fetchmail-daemon-6.3.20-0.1mdvmes5.2.i586.rpm
0abdef167f8d00f6980bda48940df1ce mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
4923eef5e0f29e72a407b4806c890008 mes5/x86_64/fetchmail-6.3.20-0.1mdvmes5.2.x86_64.rpm
19d714a319a0d7e0a823c9bb1f6a6ccf mes5/x86_64/fetchmailconf-6.3.20-0.1mdvmes5.2.x86_64.rpm
4c99cfa954f822bd413ae3e8a8ca6d7e mes5/x86_64/fetchmail-daemon-6.3.20-0.1mdvmes5.2.x86_64.rpm
0abdef167f8d00f6980bda48940df1ce mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFN7d5nmqjQ0CJFipgRAtLLAJ9VSpRLSdD8QGsKncFboVQN8CO2igCdGP8x
PzDnbLgLQyU76ed0DYpozro=
=nIBN
-----END PGP SIGNATURE-----

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus