<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>114732</bug_id>
          
          <creation_ts>2005-12-07 04:20 0000</creation_ts>
          <short_desc>net-mail/fetchmail-6.3.0 is out, and new homepage</short_desc>
          <delta_ts>2005-12-10 04:41:33 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Ebuilds</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://fetchmail.berlios.de/</bug_file_loc>
          
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>dsd@gentoo.org</reporter>
          <assigned_to>net-mail@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>dsd@gentoo.org</who>
            <bug_when>2005-12-07 04:20:51 0000</bug_when>
            <thetext>On 2005-11-30, fetchmail-6.3.0 was released, collecting bug fixes,
documentation, portability and IPv6 improvements from the preceding 777 days
since fetchmail-6.2.5&apos;s release in October 2003.

CVE-2005-2335: Fetchmail was found to contain a remotely exploitable
vulnerability in the POP3 code, affecting both the 6.2.0 and 6.2.5 releases.
6.2.5.2, 6.2.5.4 and 6.3.0 have got this bug fixed. (Other versions have not
been checked if they contain this bug.)

CVE-2005-3088: Fetchmailconf was found to open the configuration files
world-readable, writing data to them, and only then tightening up permissions,
which may cause password information to be visible to other users. This bug
affected fetchmail 6.2.0, 6.2.5 and 6.2.5.2. The bug is fixed in fetchmail
6.2.5.4 and 6.3.0.

Please update to fetchmail version 6.3.0, or, if your local updating policy does
not permit so, to 6.2.5.4 which can be obtained from the download directory.

The old homepage (http://www.catb.org/~esr/fetchmail/) is now unmaintained, as
are the old mailing lists, due to lack of admin access. The new homepage is at
http://fetchmail.berlios.de/ so the new ebuild should reflect this.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-12-10 04:41:33 0000</bug_when>
            <thetext>6.3.0 in portage. We have now finally gotten rid of old tarball from catb.org
and few deprecated patches. I&apos;ve had this on my TODO for quite some time, but
now that  minor version number changed, it&apos;s a nice opportunity to do so.

Both mentioned security vulnerabilities have already been addressed in our
ebuilds - CVE-2005-2335 in 6.2.5.2 (bug #99865) and CVE-2005-3088 in 6.2.5.2-r1
(bug #110366), so there&apos;s probably no need to call in security. Closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>