Mandrake Linux Security Advisory : fetchmail (MDKSA-2001:072)
Critical Nessus Plugin ID 13887
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionA vulnerability was found by Salvatore Sanfilippo in both the IMAP and POP3 code of fetchmail where the input is not verified and no bounds checking is done. This can be exploited by a remote attacker to write arbitrary data into memory. The attacker must have control of the mail server the client is connecting to via fetchmail in order to exploit this vulnerability.
SolutionUpdate the affected fetchmail, fetchmail-daemon and / or fetchmailconf packages.