|
|
>> Fedora Security Update Fixes Libc-client Buffer Overflow Vulnerability
|
Title : Fedora Security Update Fixes Libc-client Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2005-2814 CVE ID : CVE-2005-2933
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-09
|
Fedora has released updated packages to correct a vulnerability identified in Libc-client. This flaw is due to a stack overflow error in the "mail_valid_net_parse_work()" [src/c-client/mail.c] function that does not properly handle specially crafted mailbox names containing a quote (") character, which could be exploited by authenticated remote attackers to execute arbitrary commands with the privileges of the IMAP server. For additional information, see : VUPEN/ADV-2005-1953
Affected Products
Fedora Core 4
Fedora Core 3
Solution
Upgrade the affected packages :
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
2701b151823333732d18968f5aaa4427 SRPMS/libc-client-2002e-13.src.rpm
1eff60252308fd6098f38c6b53012070 x86_64/libc-client-2002e-13.x86_64.rpm
3db455a4372570e1c2ae720eb83a6daf x86_64/libc-client-devel-2002e-13.x86_64.rpm
d95200d605b34293745146982709360a x86_64/debug/libc-client-debuginfo-2002e-13.x86_64.rpm
f047e8de3baa36327bc2212bc4fe54e9 x86_64/libc-client-2002e-13.i386.rpm
f047e8de3baa36327bc2212bc4fe54e9 i386/libc-client-2002e-13.i386.rpm
1b2df02097ae24cc8553c923effcfab8 i386/libc-client-devel-2002e-13.i386.rpm
98cb42f9d8d4ba23f1b35f7b1d24dd7b i386/debug/libc-client-debuginfo-2002e-13.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
74e71a958021a53edfd632ca92145e8f SRPMS/libc-client-2002e-17.src.rpm
52839d60a1dedda6cec987bbf4590b07 ppc/libc-client-2002e-17.ppc.rpm
7b0f2cbe941bbb3abc4d0f54779ae217 ppc/libc-client-devel-2002e-17.ppc.rpm
c6568ccc39240ec5bcf5613a8ab94aa7 ppc/debug/libc-client-debuginfo-2002e-17.ppc.rpm
8d2660b1ce5d70f750760a1a69950d74 ppc/libc-client-2002e-17.ppc64.rpm
8791383ebfca4a12feecc83235d69352 x86_64/libc-client-2002e-17.x86_64.rpm
2323d4fe60fcf342ac0366aef688e52d x86_64/libc-client-devel-2002e-17.x86_64.rpm
293dddb99622975f39ad268453a27743 x86_64/debug/libc-client-debuginfo-2002e-17.x86_64.rpm
4a344561de695b7f15f979d640046694 x86_64/libc-client-2002e-17.i386.rpm
4a344561de695b7f15f979d640046694 i386/libc-client-2002e-17.i386.rpm
1bf275133ec054b1567fb74db13ffe7d i386/libc-client-devel-2002e-17.i386.rpm
3926fefbe75d22da13e5fdb924056396 i386/debug/libc-client-debuginfo-2002e-17.i386.rpm
References
http://www.vupen.com/english/advisories/2005/2814 http://www.frsirt.com/english/reference/2167 http://www.frsirt.com/english/reference/2168
ChangeLog
2005-12-09 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|