Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51516
Category:Conectiva Local Security Checks
Title:Conectiva Security Advisory CLA-2002:487
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory CLA-2002:487.

imap[4] is a package that contains POP2, POP3 and IMAP servers
developed at the University of Washington (UW).

Marcell Fodor published[1] a remote buffer overflow
vulnerability[2][3] in the IMAP server. This vulnerability can be
exploited by a remote attacker after he or she has been successfully
authenticated by the server. Arbitrary code could then be executed,
but with the privileges of the authenticated user.

This vulnerability only affects the IMAP server available in this
package.

The updated packages have been fixed with the patch made available by
the author[5].


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://online.securityfocus.com/archive/1/272030/2002-05-07/2002-05-13/2
http://www.securityspace.com/smysecure/catid.html?in=CLA-2002:487
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002

Risk factor : High

CVSS Score:
7.5

Cross-Ref: BugTraq ID: 4713
Common Vulnerability Exposure (CVE) ID: CVE-2002-0379
http://www.securityfocus.com/bid/4713
Bugtraq: 20020510 wu-imap buffer overflow condition (Google Search)
http://marc.info/?l=bugtraq&m=102107222100529&w=2
Caldera Security Advisory: CSSA-2002-021.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-021.0.txt
CERT/CC vulnerability note: VU#961489
http://www.kb.cert.org/vuls/id/961489
Conectiva Linux advisory: CLA-2002:487
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000487
En Garde Linux Advisory: ESA-20020607-013
http://www.linuxsecurity.com/advisories/other_advisory-2120.html
HPdes Security Advisory: HPSBTL0205-043
http://online.securityfocus.com/advisories/4167
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-034.php
http://www.redhat.com/support/errata/RHSA-2002-092.html
XForce ISS Database: wuimapd-authenticated-user-bo(10803)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10803
http://www.iss.net/security_center/static/9055.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.