Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[SECURITY] [DSA 1377-2] New fetchmail packages fix denial of service

From: Steve Kemp <skx(at)debian.org>
Date: Fri Sep 21 2007 - 12:43:46 EDT


-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

Package        : fetchmail
Vulnerability  : null pointer dereference
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2007-4565

Matthias Andree discovered that fetchmail, an SSL enabled POP3, APOP and IMAP mail gatherer/forwarder, can under certain circumstances attempt to dereference a NULL pointer and crash.

For the stable distribution (etch), this problem has been fixed in version 6.3.6-1etch1.

For the old stable distribution (sarge), this problem was not present.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your fetchmail package.

Upgrade instructions

- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

Do you need help?X

apt-get update

        will update the internal database apt-get upgrade

        will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 4.0 alias etch

- -------------------------------

i386 architecture (Intel ia32)

  http://security.debian.org/pool/updates/main/f/fetchmail/fetchmail_6.3.6-1etch1_i386.deb     Size/MD5 checksum: 641344 2eadc43a18712b3a1763094f7c837475

  These files will probably be moved into the stable distribution on   its next update.

Do you need more help?X

iD8DBQFG8/RowM/Gs81MDZ0RAsV5AJ4zq/rWuYTHRafkjTPp5Eg0cv1teACfQztf 4GE7IYiy9jSuAA5hSvi0ccI=
=Qmk2
-----END PGP SIGNATURE-----

-- 
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Fri Sep 21 12:48:42 2007

This archive was generated by hypermail 2.1.8 : Sun Oct 07 2007 - 07:58:06 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library