Jump to content

Advisories MDVSA-2010:037: fetchmail


paul
 Share

Recommended Posts

A vulnerability have been discovered and corrected in fetchmail:

 

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13,

when running in verbose mode on platforms for which char is signed,

allows remote attackers to cause a denial of service (application

crash) or possibly execute arbitrary code via an SSL X.509 certificate

containing non-printable characters with the high bit set, which

triggers a heap-based buffer overflow during escaping (CVE-2010-0562).

 

This update provides fetchmail 6.3.14, which is not vulnerable to

this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...