Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: Mail-SpamAssasin
Date: Sun, 02 Feb 2003 13:42:38
Message-Id: 20030202132113.7E4665763@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200302-01
6 - - --------------------------------------------------------------------
7
8 PACKAGE : Mail-SpamAssasin
9 SUMMARY : arbitrary code execution
10 DATE : 2003-02-02 13:25 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 - From advisory:
16
17 "Attacker may be able to execute arbitrary code by sending a specially
18 crafted e-mail to a system using SpamAssassin's spamc program in BSMTP
19 mode (-B option). Versions from 2.40 to 2.43 are affected."
20
21 Read the full advisory at
22 http://marc.theaimsgroup.com/?l=bugtraq&m=104342896818777&w=2
23
24 SOLUTION
25
26 It is recommended that all Gentoo Linux users who are running
27 dev-perl/Mail-SpamAssasin to Mail-SpamAssasin-2.44 as follows:
28
29 emerge sync
30 emerge -u Mail-SpamAssasin
31 emerge clean
32
33 - - --------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
35 - - --------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.2.1 (GNU/Linux)
38
39 iD8DBQE+PRxAfT7nyhUpoZMRAjBlAKCIBHUPx/LE/JJg130OosBtzfXNyACfY+/n
40 hQ1myVlS8MPcIc1BGzoLZzM=
41 =y8WM
42 -----END PGP SIGNATURE-----