Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes Fetchmail Password Disclosure and DoS Vulnerabilities

Title : Fedora Security Update Fixes Fetchmail Password Disclosure and DoS Vulnerabilities
VUPEN ID : VUPEN/ADV-2007-0219
CVE ID : CVE-2006-5867 - CVE-2006-5974
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-01-17


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

Fedora has released security updates to address multiple vulnerabilities identified in Fetchmail. These issues could be exploited by attackers to cause a denial of service or disclose sensitive information. For additional information, see : VUPEN/ADV-2007-0087

Affected Products

Fedora Core 6
Fedora Core 5

Solution

Upgrade the affected packages :

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

e9c1703b881155f799d839797cb55d7322680772 SRPMS/fetchmail-6.3.6-1.fc5.src.rpm
e9c1703b881155f799d839797cb55d7322680772 noarch/fetchmail-6.3.6-1.fc5.src.rpm
0282df3a830034ba9db6d33bf89472d3670c4b26 ppc/fetchmail-6.3.6-1.fc5.ppc.rpm
29e788a6de9e0c86563d0293f379d36ffba52660 ppc/debug/fetchmail-debuginfo-6.3.6-1.fc5.ppc.rpm
39947bd8fcff2f4d8ecb74926d30cc99afa897bf x86_64/debug/fetchmail-debuginfo-6.3.6-1.fc5.x86_64.rpm
571c75f756a82bc201c63098492c53c81f6f9226 x86_64/fetchmail-6.3.6-1.fc5.x86_64.rpm
b5f04d034eaf6c0940f1414820aa1f14beb199f8 i386/debug/fetchmail-debuginfo-6.3.6-1.fc5.i386.rpm
d2b9dc51f18095720ff007c8bd24a4c8988eebf6 i386/fetchmail-6.3.6-1.fc5.i386.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/

d5d7bebc3476a174ae1b3a36e31b2e84a25efa19 SRPMS/fetchmail-6.3.6-1.fc6.src.rpm
d5d7bebc3476a174ae1b3a36e31b2e84a25efa19 noarch/fetchmail-6.3.6-1.fc6.src.rpm
36fd1993cb074e0060d94df48bd9b8a7c9af9b6a ppc/fetchmail-6.3.6-1.fc6.ppc.rpm
aa879045f673cbfabeb3273893d1d0fa557e0b99 ppc/debug/fetchmail-debuginfo-6.3.6-1.fc6.ppc.rpm
074dcbf06be93dd95f82a35b5a16fcf8ac0c1967 x86_64/debug/fetchmail-debuginfo-6.3.6-1.fc6.x86_64.rpm
455a9ca94841446549fb88c3ada38c3b0da998df x86_64/fetchmail-6.3.6-1.fc6.x86_64.rpm
bddfc25846957e5c4448e3fec2be8920a2965baf i386/debug/fetchmail-debuginfo-6.3.6-1.fc6.i386.rpm
4482d10b2c4904bbeac01c12601e7e265681375c i386/fetchmail-6.3.6-1.fc6.i386.rpm

References

http://www.vupen.com/english/advisories/2007/0219
https://www.redhat.com/archives/fedora-package-announce/2007-January/msg00092.html
https://www.redhat.com/archives/fedora-package-announce/2007-January/msg00093.html

ChangeLog

2007-01-17 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy