Secunia - Stay Secure
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Fedora update for fetchmail Advisory Available in Danish  Advisory Available in German 

Secunia Advisory: SA23804  
Release Date: 2007-01-17

Critical:
Less critical
Impact: Exposure of sensitive information
DoS
Where: From local network
Solution Status: Vendor Patch

OS:Fedora Core 5
Fedora Core 6


CVE reference:CVE-2006-5867 (Secunia mirror)
CVE-2006-5974 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Fedora has issued an update for fetchmail. This fixes a vulnerability and a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and malicious people to gain knowledge of sensitive information.

For more information:
SA23631

Solution:
Apply updated packages.

-- Fedora Core 5 --

e9c1703b881155f799d839797cb55d7322680772 SRPMS/fetchmail-6.3.6-1.fc5.src.rpm
e9c1703b881155f799d839797cb55d7322680772 noarch/fetchmail-6.3.6-1.fc5.src.rpm
0282df3a830034ba9db6d33bf89472d3670c4b26 ppc/fetchmail-6.3.6-1.fc5.ppc.rpm
29e788a6de9e0c86563d0293f379d36ffba52660 ppc/debug/fetchmail-debuginfo-6.3.6-1.fc5.ppc.rpm
39947bd8fcff2f4d8ecb74926d30cc99afa897bf x86_64/debug/fetchmail-debuginfo-6.3.6-1.fc5.x86_64.rpm
571c75f756a82bc201c63098492c53c81f6f9226 x86_64/fetchmail-6.3.6-1.fc5.x86_64.rpm
b5f04d034eaf6c0940f1414820aa1f14beb199f8 i386/debug/fetchmail-debuginfo-6.3.6-1.fc5.i386.rpm
d2b9dc51f18095720ff007c8bd24a4c8988eebf6 i386/fetchmail-6.3.6-1.fc5.i386.rpm

-- Fedora Core 6 --

d5d7bebc3476a174ae1b3a36e31b2e84a25efa19 SRPMS/fetchmail-6.3.6-1.fc6.src.rpm
d5d7bebc3476a174ae1b3a36e31b2e84a25efa19 noarch/fetchmail-6.3.6-1.fc6.src.rpm
36fd1993cb074e0060d94df48bd9b8a7c9af9b6a ppc/fetchmail-6.3.6-1.fc6.ppc.rpm
aa879045f673cbfabeb3273893d1d0fa557e0b99 ppc/debug/fetchmail-debuginfo-6.3.6-1.fc6.ppc.rpm
074dcbf06be93dd95f82a35b5a16fcf8ac0c1967 x86_64/debug/fetchmail-debuginfo-6.3.6-1.fc6.x86_64.rpm
455a9ca94841446549fb88c3ada38c3b0da998df x86_64/fetchmail-6.3.6-1.fc6.x86_64.rpm
bddfc25846957e5c4448e3fec2be8920a2965baf i386/debug/fetchmail-debuginfo-6.3.6-1.fc6.i386.rpm
4482d10b2c4904bbeac01c12601e7e265681375c i386/fetchmail-6.3.6-1.fc6.i386.rpm

Original Advisory:
http://fedoranews.org/cms/node/2429
http://fedoranews.org/cms/node/2430

Other References:
SA23631:
http://secunia.com/advisories/23631/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

96 Related Secunia Security Advisories, displaying 10

1. Fedora update for samba
2. Fedora update for openoffice.org
3. Fedora update for xorg-x11-xfs
4. Fedora update for kernel
5. Fedora update for firefox
6. Fedora update for htdig
7. Fedora update for tetex
8. Fedora update for openldap
9. Fedora update for samba
10. Fedora update for cups

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
phpJobScheduler "installed_conf ig_file" File Inclusion Vulnerabilities
2.
phpMyRealty "price_max" SQL Injection Vulnerability
3.
HP TCP/IP Services for OpenVMS Finger Format String Vulnerability
4.
Novell eDirectory Multiple Vulnerabilities
5.
Sun Solaris Kernel Covert Channel Security Bypass
6.
Subdreamer Light Global Variables SQL Injection Vulnerability
7.
dotProject SQL Injection and Cross-Site Scripting
8.
Slackware update for amarok
9.
OpenOffice "rtl_allocateMe mory()" Truncation Vulnerability
10.
Acoustica Mixcraft ".mx4" File Processing Buffer Overflow





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia