Ubuntu 4.10 / 5.04 : fetchmail vulnerability (USN-153-1)

Ubuntu Security Notice (C) 2005-2013 Canonical, Inc. / NASL script (C) 2006-2013 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related patches.

Description :

Ross Boylan discovered a remote buffer overflow in fetchmail. By
sending invalid responses with very long UIDs, a faulty or malicious
POP server could crash fetchmail or execute arbitrary code with the
privileges of the user invoking fetchmail.

fetchmail is commonly run as root to fetch mail for multiple user
accounts
in this case, this vulnerability could be exploited to
compromise the whole system.

Solution :

Update the affected fetchmail, fetchmail-ssl and / or fetchmailconf
packages.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 20554 ()

Bugtraq ID:

CVE ID: CVE-2005-2335