Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian 3.1 DSA 1121-1 Critical: Postgrey Remote Format String Attack

debian
Calendar Grey July 24, 2006
Debian Logo
A vulnerability has been discovered in postgrey for Debian that could trigger a remote denial of service. Users are strongly urged to apply the suggested updates to resolve this issue
Peter Bieringer discovered that postgrey, an greylisting implementation for Postfix, is vulnerable to a format string attack that allows remote attackers to the daemon.

Summary


For the stable distribution (sarge) this problem has also been fixed
in version 1.21-1volatile4 in the volatile archive.

For the unstable distribution (sid) this problem has been fixed in
version 1.22-1.

We recommend that you upgrade your postgrey package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given at the end of this advisory:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge

Size/MD5 checksum: 628 2a0d8c903c9f47b374a9fa871056b5df
Size/MD5 checksum: 13354 96eefd0e11745edf1cce5fa833d83396
Size/MD5 checksum: 25934 1274e073be5178445e0892a9dcc6fe98

Archi...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here