Gentoo Archives: gentoo-announce

From: aliz@gentoo.org (Daniel Ahlberg)
To: gentoo-announce@g.o, bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com
Subject: [gentoo-announce] GLSA: teapop (200309-18)
Date: Tue, 30 Sep 2003 20:53:07
Message-Id: 20030930205230.79AC49FB26@noc.internal.fairytale.se
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200309-18
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : teapop
9           SUMMARY : sql injection
10              DATE : 2003-09-30 20:52 UTC
11           EXPLOIT : remote
12 GENTOO BUG # : 26730
13               CVE : CAN-2003-0515
14
15 - - - ---------------------------------------------------------------------
16
17 DESCRIPTION
18
19 teapop suffers from a sql injection in the postgresql and mysql
20 authentication module.
21
22 SOLUTION
23
24 it is recommended that all Gentoo Linux users who are running
25 net-mail/teapop upgrade to a fixed version.
26
27 make sure that the version to be installed is atleast 0.3.7.
28
29 emerge sync
30 emerge teapop -p
31 emerge teapop
32 emerge clean
33
34
35 - - - ---------------------------------------------------------------------
36 aliz@g.o - GnuPG key is available at http://dev.gentoo.org/~aliz
37 - - - ---------------------------------------------------------------------
38 -----BEGIN PGP SIGNATURE-----
39 Version: GnuPG v1.2.3 (GNU/Linux)
40
41 iD8DBQE/ee0OfT7nyhUpoZMRAlmhAJ9THOKIyx0nc4azr1m0nr3WL4np0ACgllB6
42 6ztPlNoz+4lolEgTATKE/so=
43 =Z13m
44 -----END PGP SIGNATURE-----