Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] GLSA: MailTools
Date: Wed, 06 Nov 2002 15:13:49
Message-Id: 20021106144756.31EEC33762@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200211-001
6 - - --------------------------------------------------------------------
7
8 PACKAGE : MailTools
9 SUMMARY : remote command execution
10 DATE    : 2002-11-06 14:11 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 The SuSE Security Team reviewed critical Perl modules, including the
16 Mail::Mailer package. This package contains a security hole which allows
17 remote attackers to execute arbitrary commands in certain circumstances.
18 This is due to the usage of mailx as default mailer which allows commands
19 to be embedded in the mail body.
20 Vulnerable to this attack are custom auto reply programs or spam filters
21 which use Mail::Mailer directly or indirectly.
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 dev-perl/MailTools-1.44-r1 and earlier update their systems as follows:
27
28 emerge rsync
29 emerge MailTools
30 emerge clean
31
32 - - --------------------------------------------------------------------
33 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
34 - - --------------------------------------------------------------------
35 -----BEGIN PGP SIGNATURE-----
36 Version: GnuPG v1.0.7 (GNU/Linux)
37
38 iD8DBQE9ySubfT7nyhUpoZMRAgIeAJ4zSYKNfFatgEwUaq/6pskWFY333wCeLBvG
39 9WiQs7LM4yGUDNk0jH/k/Fw=
40 =ZOPv
41 -----END PGP SIGNATURE-----
42
43 --
44 gentoo-announce@g.o mailing list