Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: qpopper (200303-12)
Date: Mon, 17 Mar 2003 10:25:50
Message-Id: 20030317095024.096CA5762@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200303-12
6 - - ---------------------------------------------------------------------
7
8 PACKAGE : qpopper
9 SUMMARY : buffer overflow
10 DATE : 2003-03-17 09:50 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <4.0.5
13 FIXED VERSION : >=4.0.5
14 CVE : CAN-2003-0143
15
16 - - ---------------------------------------------------------------------
17
18 - From advisory:
19
20 "Under certain conditions it is possible to execute arbitrary code using
21 a buffer overflow in the recent qpopper.
22
23 You need a valid username/password-combination and code is (depending on
24 the setup) usually executed with the user's uid and gid mail."
25
26 Read the full advisory at:
27 http://marc.theaimsgroup.com/?l=bugtraq&m=104739841223916&w=2
28
29 SOLUTION
30
31 It is recommended that all Gentoo Linux users who are running
32 net-mail/qpopper upgrade to qpopper-4.0.5 as follows:
33
34 emerge sync
35 emerge qpopper
36 emerge clean
37
38 - - ---------------------------------------------------------------------
39 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
40 - - ---------------------------------------------------------------------
41 -----BEGIN PGP SIGNATURE-----
42 Version: GnuPG v1.2.1 (GNU/Linux)
43
44 iD8DBQE+dZp5fT7nyhUpoZMRAq9XAJsFyPbrwFb1CcvL59jEKtAoymZzTwCeIw4Z
45 p8IXHapfnjyZM1j7pcN+nW8=
46 =OPDK
47 -----END PGP SIGNATURE-----