Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.54117
Category:SuSE Local Security Checks
Title:SuSE Security Advisory SUSE-SA:2003:001 (fetchmail)
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory SUSE-SA:2003:001.

fetchmail is used to download emails from POP-, IMAP-, ETRN- or ODMR-
servers.

Stefan Esser of e-matters reported a bug in fetchmail's mail address
expanding code which can lead to remote system compromise.
When fetchmail expands email addresses in mail headers it doesn not
allocated enough memory. An attacker can send a malicious formatted mail
header to exhaust the memory allocated by fetchmail to overwrite parts of
the heap. This can be exploited to execute arbitrary code.

Solution:
Update your system with the packages as indicated in
the referenced security advisory.

http://www.securityspace.com/smysecure/catid.html?in=SUSE-SA:2003:001

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1365
BugTraq ID: 6390
http://www.securityfocus.com/bid/6390
Bugtraq: 20021213 Advisory 05/2002: Another Fetchmail Remote Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=103979751818638&w=2
Bugtraq: 20021215 GLSA: fetchmail (Google Search)
http://marc.info/?l=bugtraq&m=104004858802000&w=2
Caldera Security Advisory: CSSA-2003-001.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-001.0.txt
Conectiva Linux advisory: CLA-2002:554
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000554
Debian Security Information: DSA-216 (Google Search)
http://www.debian.org/security/2002/dsa-216
En Garde Linux Advisory: ESA-20030127-002
Immunix Linux Advisory: IMNX-2003-7+-023-01
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:011
http://security.e-matters.de/advisories/052002.html
http://www.redhat.com/support/errata/RHSA-2002-293.html
http://www.redhat.com/support/errata/RHSA-2002-294.html
http://www.redhat.com/support/errata/RHSA-2003-155.html
SuSE Security Announcement: SuSE-SA:2003:001 (Google Search)
XForce ISS Database: fetchmail-address-header-bo(10839)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10839
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.