Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Gentoo: 200303-12 Critical: Qpopper Buffer Overflow Remote Execute

gentoo
Calendar Grey March 17, 2003
Dist Gentoo Esm H88
Gentoo Linux security advisory 200303-12 addresses critical qpopper buffer overflow risk requiring immediate update.
Under certain conditions it is possible to execute arbitrary code using a buffer overflow in the recent qpopper.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-12
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
- From advisory:
"Under certain conditions it is possible to execute arbitrary code using a buffer overflow in the recent qpopper.
You need a valid username/password-combination and code is (depending on the setup) usually executed with the user's uid and gid mail."
Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=104739841223916&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running net-mail/qpopper upgrade to qpopper-4.0.5 as follows:
emerge sync emerge qpopper emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------
4.0.5

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : qpopper
SUMMARY : buffer overflow
DATE : 2003-03-17 09:50 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <4.0.5 : fixed version>=4.0.5
CVE : CAN-2003-0143

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here