Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 37717
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Gustavo Zacarias (RETIRED) <gustavoz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 37717 depends on: Show dependency tree
Bug 37717 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-01-09 10:50 0000
A specially-crafted email can make fetchmail crash.
Check:
http://xforce.iss.net/xforce/xfdb/13450
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0792

------- Comment #1 From Martin Holzer (RETIRED) 2004-02-09 13:09:09 0000 -------
6.2.5 is in cvs

------- Comment #2 From Joshua J. Berry (CondorDes) (RETIRED) 2004-03-26 13:21:17 0000 -------
Is this getting moved to stable anytime soon?

------- Comment #3 From Seemant Kulleen (RETIRED) 2004-03-26 13:43:13 0000 -------
stabled on x86

------- Comment #4 From Seemant Kulleen (RETIRED) 2004-03-26 13:44:08 0000 -------
the problem will be the alpha arch, because 6.2.5 appears masked on alpha, but
earlier versions are stable on there.  can we get some alpha people on this?

------- Comment #5 From Jay Maynard (RETIRED) 2004-03-26 15:45:16 0000 -------
Unable to reproduce the header corruption that resulted in 6.2.4 being masked
on Alpha. Marked stable.

------- Comment #6 From Joshua J. Berry (CondorDes) (RETIRED) 2004-03-29 18:08:21 0000 -------
I've submitted a draft GLSA for this bug (id ddc13b8a4b951395bc251f69ef1920e9).

I don't much like the Description field in the GLSA, but I couldn't find any more detailed information to include. :-/

------- Comment #7 From Kurt Lieber 2004-03-29 23:35:46 0000 -------
PPC -- latest stable version of fetchmail for ppc is 5.9.14.  Can someone look
at 6.2.5 and see if it can be marked stable?

AMD64 -- the 6.2.5 ebuild has amd64-specific stuff in it ("use amd64" fex) but
there are no amd64 keywords.  Can you double-check?

Also adding other arches.  

------- Comment #8 From Lars Weiler (RETIRED) 2004-03-30 03:39:03 0000 -------
It's now stable on ppc.  Removing from Cc.

------- Comment #9 From Jon Portnoy (RETIRED) 2004-03-30 06:47:56 0000 -------
Stable on AMD64

------- Comment #10 From Kurt Lieber 2004-03-31 00:16:10 0000 -------
GLSA 200403-10

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug