MDVSA-2010:037 -- Mandriva fetchmailID: oval:org.secpod.oval:def:300242 | Date: (C)2012-01-07 (M)2021-06-02 |
Class: PATCH | Family: unix |
A vulnerability have been discovered and corrected in fetchmail: The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping . This update provides fetchmail 6.3.14, which is not vulnerable to this issue.
Platform: |
Mandriva Linux 2010.0 |