-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 _______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2011:107 http://www.mandriva.com/security/ _______________________________________________________________________ Package : fetchmail Date : June 7, 2011 Affected: 2009.0, 2010.1, Corporate 4.0, Enterprise Server 5.0 _______________________________________________________________________ Problem Description: Multiple vulnerabilities were discovered and corrected in fetchmail: fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted (1) message header or (2) POP3 UIDL list (CVE-2010-1167). NOTE: This vulnerability did not affect Mandriva Linux 2010.2. fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets (CVE-2011-1947). Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more: http://store.mandriva.com/product_info.php?cPath=149&products_id=490 The updated packages have been upgraded to the 6.3.20 version which is not vulnerable to these issues. _______________________________________________________________________ References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1167 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1947 http://seclists.org/oss-sec/2011/q2/551 _______________________________________________________________________ Updated Packages: Mandriva Linux 2009.0: fa463380143ddd8b37d761fa02bdcd4d 2009.0/i586/fetchmail-6.3.20-0.1mdv2009.0.i586.rpm 33c88d95440a52ff3baa229b132f9cc7 2009.0/i586/fetchmailconf-6.3.20-0.1mdv2009.0.i586.rpm a07c07a7ed25d8ece92eb2bba3cb8052 2009.0/i586/fetchmail-daemon-6.3.20-0.1mdv2009.0.i586.rpm d06dc796666631cc2c33470366413380 2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm Mandriva Linux 2009.0/X86_64: d068668a5be3b422ac49ee68376ef2f2 2009.0/x86_64/fetchmail-6.3.20-0.1mdv2009.0.x86_64.rpm 5d586cf7cbaa5a661bef2b79a32f9841 2009.0/x86_64/fetchmailconf-6.3.20-0.1mdv2009.0.x86_64.rpm 3d6f73e1b46c7b154b4ade245498642b 2009.0/x86_64/fetchmail-daemon-6.3.20-0.1mdv2009.0.x86_64.rpm d06dc796666631cc2c33470366413380 2009.0/SRPMS/fetchmail-6.3.20-0.1mdv2009.0.src.rpm Mandriva Linux 2010.1: 4e1f0cf13ad4dd13de33e598b54ed10c 2010.1/i586/fetchmail-6.3.20-0.1mdv2010.2.i586.rpm 9d99d5360bacbee18a354b40d73dbdce 2010.1/i586/fetchmailconf-6.3.20-0.1mdv2010.2.i586.rpm 00595fe4b19c6de7a788a2669ca27c1e 2010.1/i586/fetchmail-daemon-6.3.20-0.1mdv2010.2.i586.rpm 580622099149b837d73746ea58d6e401 2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm Mandriva Linux 2010.1/X86_64: 727d0e55ff5c10a6d61642be1ba243ec 2010.1/x86_64/fetchmail-6.3.20-0.1mdv2010.2.x86_64.rpm dc672cd266a8e8267170e790f797a706 2010.1/x86_64/fetchmailconf-6.3.20-0.1mdv2010.2.x86_64.rpm 04284804437e9d6b0ac3cf451483a52e 2010.1/x86_64/fetchmail-daemon-6.3.20-0.1mdv2010.2.x86_64.rpm 580622099149b837d73746ea58d6e401 2010.1/SRPMS/fetchmail-6.3.20-0.1mdv2010.2.src.rpm Corporate 4.0: 835fbe8cccecac21c87856a74fc630e1 corporate/4.0/i586/fetchmail-6.3.20-0.1.20060mlcs4.i586.rpm 98246f052294392137bf7c796a9e27f9 corporate/4.0/i586/fetchmailconf-6.3.20-0.1.20060mlcs4.i586.rpm f678d210a8d3784c661a7ff53cf70d90 corporate/4.0/i586/fetchmail-daemon-6.3.20-0.1.20060mlcs4.i586.rpm 33abcf7dea9f25d8a752cbb93f0f436f corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm Corporate 4.0/X86_64: 2da71f289543859e9665988dcc36e12b corporate/4.0/x86_64/fetchmail-6.3.20-0.1.20060mlcs4.x86_64.rpm 44bf90966c95ccaf70eebadd8c774463 corporate/4.0/x86_64/fetchmailconf-6.3.20-0.1.20060mlcs4.x86_64.rpm 83c9e6d7b456a195197cba0834fa1a4b corporate/4.0/x86_64/fetchmail-daemon-6.3.20-0.1.20060mlcs4.x86_64.rpm 33abcf7dea9f25d8a752cbb93f0f436f corporate/4.0/SRPMS/fetchmail-6.3.20-0.1.20060mlcs4.src.rpm Mandriva Enterprise Server 5: 9978d5caa0f8b529ca65f372318e7def mes5/i586/fetchmail-6.3.20-0.1mdvmes5.2.i586.rpm 4e6d7445d7fe568dc8318a8307a032d9 mes5/i586/fetchmailconf-6.3.20-0.1mdvmes5.2.i586.rpm 82e050b23068208becda3b2efe691626 mes5/i586/fetchmail-daemon-6.3.20-0.1mdvmes5.2.i586.rpm 0abdef167f8d00f6980bda48940df1ce mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm Mandriva Enterprise Server 5/X86_64: 4923eef5e0f29e72a407b4806c890008 mes5/x86_64/fetchmail-6.3.20-0.1mdvmes5.2.x86_64.rpm 19d714a319a0d7e0a823c9bb1f6a6ccf mes5/x86_64/fetchmailconf-6.3.20-0.1mdvmes5.2.x86_64.rpm 4c99cfa954f822bd413ae3e8a8ca6d7e mes5/x86_64/fetchmail-daemon-6.3.20-0.1mdvmes5.2.x86_64.rpm 0abdef167f8d00f6980bda48940df1ce mes5/SRPMS/fetchmail-6.3.20-0.1mdvmes5.2.src.rpm _______________________________________________________________________ To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/security/advisories If you want to report vulnerabilities, please contact security_(at)_mandriva.com _______________________________________________________________________ Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Mandriva Security Team -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFN7d5nmqjQ0CJFipgRAtLLAJ9VSpRLSdD8QGsKncFboVQN8CO2igCdGP8x PzDnbLgLQyU76ed0DYpozro= =nIBN -----END PGP SIGNATURE-----