Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: uw-imapd (200305-12)
Date: Sun, 01 Jun 2003 12:02:34
Message-Id: 20030601115425.388AC336F4@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200305-12
6 - - - ---------------------------------------------------------------------
7
8 PACKAGE : uw-imapd
9 SUMMARY : buffer overflow
10 DATE : 2003-06-01 11:54 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <uw-imapd-2002d
13 FIXED VERSION : >=uw-imapd-2002d
14 CVE :
15
16 - - - ---------------------------------------------------------------------
17
18 - From advisory:
19
20 "UW-imapd can also act as IMAP client, allowing user to connect to specified
21 server. It is disabled for anonymous users, but allowed for everyone else
22 (even with closedBox, blackBox or restrictBox enabled). So exploiting it
23 could give you access to the system as the logged in user."
24
25 Read the full advisory at:
26 http://marc.theaimsgroup.com/?l=bugtraq&m=105294024124163&w=2
27
28 SOLUTION
29
30 It is recommended that all Gentoo Linux users who are running
31 net-mail/uw-imapd upgrade to uw-imapd-2002d as follows
32
33 emerge sync
34 emerge uw-imapd
35 emerge clean
36
37 - - - ---------------------------------------------------------------------
38 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
39 prez@g.o
40 - - - ---------------------------------------------------------------------
41 -----BEGIN PGP SIGNATURE-----
42 Version: GnuPG v1.2.2 (GNU/Linux)
43
44 iD8DBQE+2elufT7nyhUpoZMRAmlOAKCitC0oKI/kdV6MvKwGUoa5j5K3AwCgvY+8
45 aMWvvFF6iPRICVvdY7/ipYc=
46 =nEu+
47 -----END PGP SIGNATURE-----