Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57835
Category:Slackware Local Security Checks
Title:Slackware: Security Advisory (SSA:2007-024-01)
Summary:The remote host is missing an update for the 'fetchmail' package(s) announced via the SSA:2007-024-01 advisory.
Description:Summary:
The remote host is missing an update for the 'fetchmail' package(s) announced via the SSA:2007-024-01 advisory.

Vulnerability Insight:
New fetchmail packages are available for Slackware 8.1, 9.0, 9.1, 10.0,
10.1, 10.2, and 11.0 to fix a security issue.

More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:

[links moved to references]


Here are the details from the Slackware 11.0 ChangeLog:
+--------------------------+
patches/packages/fetchmail-6.3.6-i486-1_slack11.0.tgz:
Upgraded to fetchmail-6.3.6. This fixes two security issues. First, a bug
introduced in fetchmail-6.3.5 could cause fetchmail to crash. However,
no stable version of Slackware ever shipped fetchmail-6.3.5. Second, a long
standing bug (reported by Isaac Wilcox) could cause fetchmail to send a
password in clear text or omit using TLS even when configured otherwise.
All fetchmail users are encouraged to consider using getmail, or to upgrade
to the new fetchmail packages.
For more information, see:
[links moved to references]
(* Security fix *)
+--------------------------+

Affected Software/OS:
'fetchmail' package(s) on Slackware 8.1, Slackware 9.0, Slackware 9.1, Slackware 10.0, Slackware 10.1, Slackware 10.2, Slackware 11.0.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-5867
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
BugTraq ID: 21903
http://www.securityfocus.com/bid/21903
Bugtraq: 20070105 fetchmail security announcement 2006-02 (CVE-2006-5867) (Google Search)
http://www.securityfocus.com/archive/1/456115/100/0/threaded
Bugtraq: 20070218 Re: [SECURITY] [DSA 1259-1] New fetchmail packages fix information disclosure (Google Search)
http://www.securityfocus.com/archive/1/460528/100/0/threaded
Cert/CC Advisory: TA07-109A
http://www.us-cert.gov/cas/techalerts/TA07-109A.html
Debian Security Information: DSA-1259 (Google Search)
http://www.debian.org/security/2007/dsa-1259
http://fedoranews.org/cms/node/2429
http://security.gentoo.org/glsa/glsa-200701-13.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:016
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.004.html
http://osvdb.org/31580
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10566
http://www.redhat.com/support/errata/RHSA-2007-0018.html
http://securitytracker.com/id?1017478
http://secunia.com/advisories/23631
http://secunia.com/advisories/23695
http://secunia.com/advisories/23714
http://secunia.com/advisories/23781
http://secunia.com/advisories/23804
http://secunia.com/advisories/23838
http://secunia.com/advisories/23923
http://secunia.com/advisories/24007
http://secunia.com/advisories/24151
http://secunia.com/advisories/24174
http://secunia.com/advisories/24284
http://secunia.com/advisories/24966
SGI Security Advisory: 20070201-01-P
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.517995
SuSE Security Announcement: SUSE-SR:2007:004 (Google Search)
http://www.novell.com/linux/security/advisories/2007_4_sr.html
http://www.trustix.org/errata/2007/0007
http://www.ubuntu.com/usn/usn-405-1
http://www.vupen.com/english/advisories/2007/0087
http://www.vupen.com/english/advisories/2007/0088
http://www.vupen.com/english/advisories/2007/1470
Common Vulnerability Exposure (CVE) ID: CVE-2006-5974
BugTraq ID: 21902
http://www.securityfocus.com/bid/21902
Bugtraq: 20070105 fetchmail security announcement 2006-03 (CVE-2006-5974) (Google Search)
http://www.securityfocus.com/archive/1/456114/100/0/threaded
http://osvdb.org/31836
http://securitytracker.com/id?1017479
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.