Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 120218 - Fetchmail DoS in < 6.3.2 (including 6.3.2 RC's)
Summary: Fetchmail DoS in < 6.3.2 (including 6.3.2 RC's)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Net-Mail Packages
URL: http://fetchmail.berlios.de/fetchmail...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-01-24 13:05 UTC by Rob M.
Modified: 2006-01-24 14:10 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Rob M. 2006-01-24 13:05:38 UTC
incorrect freeing of a invalid pointer when bouncing a message to the originator or local postmaster causes DoS on fetchmail < 6.3.2, including all Fetchmail 6.3.2-Release Candidates.

Resolution: upgrade to 6.3.2 - 6.2.x is End of Lifed.

Advisory in URL.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2006-01-24 14:00:36 UTC
the stable version is unaffected and the latest unstable version is fixed, too:  nothing left to do for security here, reassigning this to net-mail, maybe you want to remove 6.3.0 and 6.3.1?
Comment 2 Torsten Veller (RETIRED) gentoo-dev 2006-01-24 14:10:33 UTC
removed 6.3.0 and 6.3.1.