exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2011-107

Mandriva Linux Security Advisory 2011-107
Posted Jun 7, 2011
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2011-107 - fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted message header or POP3 UIDL list. fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a STLS request, which allows remote servers to cause a denial of service by acknowledging the request but not sending additional packets.

tags | advisory, remote, denial of service
systems | linux, mandriva
advisories | CVE-2010-1167, CVE-2011-1947
SHA-256 | f76d34b17f631223e59aa2ba6e51c25370839677d0b8989b2ea46fc400d18a12

Mandriva Linux Security Advisory 2011-107

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2011:107
http://www.mandriva.com/security/
_______________________________________________________________________

Package : fetchmail
Date : June 7, 2011
Affected: 2009.0, 2010.1, Corporate 4.0, Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities were discovered and corrected in fetchmail:

fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does
not properly handle invalid characters in a multi-character locale,
which allows remote attackers to cause a denial of service (memory
consumption and application crash) via a crafted (1) message header or
(2) POP3 UIDL list (CVE-2010-1167). NOTE: This vulnerability did not
affect Mandriva Linux 2010.2.

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait
time after issuing a (1) STARTTLS or (2) STLS request, which allows
remote servers to cause a denial of service (application hang)
by acknowledging the request but not sending additional packets
(CVE-2011-1947).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

The updated packages have been upgraded to the 6.3.20 version which
is not vulnerable to these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1167
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1947
http://seclists.org/oss-sec/2011/q2/551
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2009.0:
fa463380143ddd8b37d761fa02bdcd4d 2009.0/i586/fetchmail-6.3.20-0.1mdv2009.0.i586.rpm
33c88d95440a52ff3baa229b132f9cc7 2009.0/i586/fetchmailconf-6.3.20-0.1mdv2009.0.i586.rpm
a07c07a7ed25d8ece92eb2bba3cb8052 2009.0/i586/fetchmail-daemon-6.3.20-0.1mdv2009.0.i586.rpm
d06dc796666631cc2c33470366413380 2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
d068668a5be3b422ac49ee68376ef2f2 2009.0/x86_64/fetchmail-6.3.20-0.1mdv2009.0.x86_64.rpm
5d586cf7cbaa5a661bef2b79a32f9841 2009.0/x86_64/fetchmailconf-6.3.20-0.1mdv2009.0.x86_64.rpm
3d6f73e1b46c7b154b4ade245498642b 2009.0/x86_64/fetchmail-daemon-6.3.20-0.1mdv2009.0.x86_64.rpm
d06dc796666631cc2c33470366413380 2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm

Mandriva Linux 2010.1:
4e1f0cf13ad4dd13de33e598b54ed10c 2010.1/i586/fetchmail-6.3.20-0.1mdv2010.2.i586.rpm
9d99d5360bacbee18a354b40d73dbdce 2010.1/i586/fetchmailconf-6.3.20-0.1mdv2010.2.i586.rpm
00595fe4b19c6de7a788a2669ca27c1e 2010.1/i586/fetchmail-daemon-6.3.20-0.1mdv2010.2.i586.rpm
580622099149b837d73746ea58d6e401 2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

Mandriva Linux 2010.1/X86_64:
727d0e55ff5c10a6d61642be1ba243ec 2010.1/x86_64/fetchmail-6.3.20-0.1mdv2010.2.x86_64.rpm
dc672cd266a8e8267170e790f797a706 2010.1/x86_64/fetchmailconf-6.3.20-0.1mdv2010.2.x86_64.rpm
04284804437e9d6b0ac3cf451483a52e 2010.1/x86_64/fetchmail-daemon-6.3.20-0.1mdv2010.2.x86_64.rpm
580622099149b837d73746ea58d6e401 2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm

Corporate 4.0:
835fbe8cccecac21c87856a74fc630e1 corporate/4.0/i586/fetchmail-6.3.20-0.1.20060mlcs4.i586.rpm
98246f052294392137bf7c796a9e27f9 corporate/4.0/i586/fetchmailconf-6.3.20-0.1.20060mlcs4.i586.rpm
f678d210a8d3784c661a7ff53cf70d90 corporate/4.0/i586/fetchmail-daemon-6.3.20-0.1.20060mlcs4.i586.rpm
33abcf7dea9f25d8a752cbb93f0f436f corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
2da71f289543859e9665988dcc36e12b corporate/4.0/x86_64/fetchmail-6.3.20-0.1.20060mlcs4.x86_64.rpm
44bf90966c95ccaf70eebadd8c774463 corporate/4.0/x86_64/fetchmailconf-6.3.20-0.1.20060mlcs4.x86_64.rpm
83c9e6d7b456a195197cba0834fa1a4b corporate/4.0/x86_64/fetchmail-daemon-6.3.20-0.1.20060mlcs4.x86_64.rpm
33abcf7dea9f25d8a752cbb93f0f436f corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm

Mandriva Enterprise Server 5:
9978d5caa0f8b529ca65f372318e7def mes5/i586/fetchmail-6.3.20-0.1mdvmes5.2.i586.rpm
4e6d7445d7fe568dc8318a8307a032d9 mes5/i586/fetchmailconf-6.3.20-0.1mdvmes5.2.i586.rpm
82e050b23068208becda3b2efe691626 mes5/i586/fetchmail-daemon-6.3.20-0.1mdvmes5.2.i586.rpm
0abdef167f8d00f6980bda48940df1ce mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
4923eef5e0f29e72a407b4806c890008 mes5/x86_64/fetchmail-6.3.20-0.1mdvmes5.2.x86_64.rpm
19d714a319a0d7e0a823c9bb1f6a6ccf mes5/x86_64/fetchmailconf-6.3.20-0.1mdvmes5.2.x86_64.rpm
4c99cfa954f822bd413ae3e8a8ca6d7e mes5/x86_64/fetchmail-daemon-6.3.20-0.1mdvmes5.2.x86_64.rpm
0abdef167f8d00f6980bda48940df1ce mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFN7d5nmqjQ0CJFipgRAtLLAJ9VSpRLSdD8QGsKncFboVQN8CO2igCdGP8x
PzDnbLgLQyU76ed0DYpozro=
=nIBN
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close