![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.51516 |
Category: | Conectiva Local Security Checks |
Title: | Conectiva Security Advisory CLA-2002:487 |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing updates announced in advisory CLA-2002:487. imap[4] is a package that contains POP2, POP3 and IMAP servers developed at the University of Washington (UW). Marcell Fodor published[1] a remote buffer overflow vulnerability[2][3] in the IMAP server. This vulnerability can be exploited by a remote attacker after he or she has been successfully authenticated by the server. Arbitrary code could then be executed, but with the privileges of the authenticated user. This vulnerability only affects the IMAP server available in this package. The updated packages have been fixed with the patch made available by the author[5]. Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade' http://online.securityfocus.com/archive/1/272030/2002-05-07/2002-05-13/2 http://www.securityspace.com/smysecure/catid.html?in=CLA-2002:487 http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002 Risk factor : High CVSS Score: 7.5 |
Cross-Ref: |
BugTraq ID: 4713 Common Vulnerability Exposure (CVE) ID: CVE-2002-0379 http://www.securityfocus.com/bid/4713 Bugtraq: 20020510 wu-imap buffer overflow condition (Google Search) http://marc.info/?l=bugtraq&m=102107222100529&w=2 Caldera Security Advisory: CSSA-2002-021.0 ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-021.0.txt CERT/CC vulnerability note: VU#961489 http://www.kb.cert.org/vuls/id/961489 Conectiva Linux advisory: CLA-2002:487 http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000487 En Garde Linux Advisory: ESA-20020607-013 http://www.linuxsecurity.com/advisories/other_advisory-2120.html HPdes Security Advisory: HPSBTL0205-043 http://online.securityfocus.com/advisories/4167 http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-034.php http://www.redhat.com/support/errata/RHSA-2002-092.html XForce ISS Database: wuimapd-authenticated-user-bo(10803) https://exchange.xforce.ibmcloud.com/vulnerabilities/10803 http://www.iss.net/security_center/static/9055.php |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |