Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Debian: DSA 732-1 Critical: Mailutils Remote Code Execution Issues

debian
Calendar Grey June 3, 2005
Scroller Debian
- --------------------------------------------------------------------------Debian Security Advisory
Updated package.

Summary


Buffer overflow mail header handling may allow a remote attacker
to execute commands with the privileges of the targeted user.

CAN-2005-1521

Combined integer and heap overflow in the fetch routine can lead
to the execution of arbitrary code.

CAN-2005-1522

Denial of service in the fetch routine.

CAN-2005-1523

Format string vulnerability can lead to the execution of arbitrary
code.

For the stable distribution (woody) these problems have been fixed in
version 20020409-1woody2.

For the testing distribution (sarge) these problems have been fixed in
version 0.6.1-4.

For the unstable distribution (sid) these problems have been fixed in
version 0.6.1-4.

We recommend that you upgrade your mailutils packages.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-ge...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.