Mandrake Linux Security Advisory : fetchmail (MDKSA-2002:036)
Medium Nessus Plugin ID 13941
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionA problem was discovered with versions of fetchmail prior to 5.9.10 that was triggered by retreiving mail from an IMAP server. The fetchmail client will allocate an array to store the sizes of the messages it is attempting to retrieve. This array size is determined by the number of messages the server is claiming to have, and fetchmail would not check whether or not the number of messages the server was claiming was too high. This would allow a malicious server to make the fetchmail process write data outside of the array bounds.
SolutionUpdate the affected fetchmail, fetchmail-daemon and / or fetchmailconf packages.