RHEL 4 : libc-client (RHSA-2005:848)
High Nessus Plugin ID 20269
SynopsisThe remote Red Hat host is missing one or more security updates.
DescriptionUpdated libc-client packages that fix a buffer overflow issue are now available.
This update has been rated as having moderate security impact by the Red Hat Security Response Team.
C-client is a common API for accessing mailboxes.
A buffer overflow flaw was discovered in the way C-client parses user-supplied mailboxes. If an authenticated user requests a specially crafted mailbox name, it may be possible to execute arbitrary code on a server that uses C-client to access mailboxes. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-2933 to this issue.
All users of libc-client should upgrade to these updated packages, which contain a backported patch that resolves this issue.
SolutionUpdate the affected libc-client and / or libc-client-devel packages.