Mandrake Linux Security Advisory : imap (MDKSA-2002:034)
High Nessus Plugin ID 13940
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionA buffer overflow was discovered in the imap server that could allow a malicious user to run code on the server with the uid and gid of the email owner by constructing a malformed request that would trigger the buffer overflow. However, the user must successfully authenticate to the imap service in order to exploit it, which limits the scope of the vulnerability somewhat, unless you are a free mail provider or run a mail service where users do not already have shell access to the system.
SolutionUpdate the affected imap and / or imap-devel packages.