Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1685-1] New uw-imap packages fix multiple vulnerabiliti

    From Steffen Joeris@1:229/2 to All on Fri Dec 12 07:40:09 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1685-1 [email protected] http://www.debian.org/security/ Steffen Joeris December 12, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : uw-imap
    Vulnerability : buffer overflows, null pointer dereference
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2008-5005 CVE-2008-5006

    Two vulnerabilities have been found in uw-imap, an IMAP
    implementation. The Common Vulnerabilities and Exposures project
    identifies the following problems:

    It was discovered that several buffer overflows can be triggered via a
    long folder extension argument to the tmail or dmail program. This
    could lead to arbitrary code execution (CVE-2008-5005).

    It was discovered that a NULL pointer dereference could be triggered by
    a malicious response to the QUIT command leading to a denial of service (CVE-2008-5006).

    For the stable distribution (etch), these problems have been fixed in
    version 2002edebian1-13.1+etch1.

    For the unstable distribution (sid) and the testing distribution
    (lenny), these problems have been fixed in version 2007d~dfsg-1.

    We recommend that you upgrade your uw-imap packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imap_2002edebian1.orig.tar.gz
    Size/MD5 checksum: 1517069 8ff277e7831326988d0ee0bfeca7c8ff
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imap_2002edebian1-13.1+etch1.dsc
    Size/MD5 checksum: 874 ac3703de07e1cf10e7aa72a10a5fb20b
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imap_2002edebian1-13.1+etch1.diff.gz
    Size/MD5 checksum: 99906 6c0172a213d199583e0d6c1dc5957a20

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/u/uw-imap/ipopd-ssl_2002edebian1-13.1+etch1_all.deb
    Size/MD5 checksum: 20760 b418a43ee29d858752497a83897588c9
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd-ssl_2002edebian1-13.1+etch1_all.deb
    Size/MD5 checksum: 20756 4381ee8fe7865bc2fbf4f83f44ddd0e3

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_alpha.deb
    Size/MD5 checksum: 50618 972cf2d773feb8547ba6cc0bd933dbea
    http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_alpha.deb
    Size/MD5 checksum: 650718 1d084bff43e5efde07706f8b54134625
    http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_alpha.deb
    Size/MD5 checksum: 47364 d1550ecb166961b3dd7c948fd7333e18
    http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_alpha.deb
    Size/MD5 checksum: 26688 9a2ed6fd202bd4b7dfbd555170664979
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_alpha.deb
    Size/MD5 checksum: 80168 d26aa9867204cbc27107bc0eb046649a
    http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_alpha.deb
    Size/MD5 checksum: 1196482 41dba8f6a0cc1b7c602060ddf3dae58c

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_amd64.deb
    Size/MD5 checksum: 1040748 89a2bb86ee48bbc3ce0ce6ac06736e5d
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_amd64.deb
    Size/MD5 checksum: 76348 e2506d3191e383e511b73851f7b2403d
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_amd64.deb
    Size/MD5 checksum: 50416 9db96b845240094cb130050463e5b8da
    http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_amd64.deb
    Size/MD5 checksum: 606040 458cf8d820a650978eed89b234c2d018
    http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_amd64.deb
    Size/MD5 checksum: 46470 a6f2e3922fdd861d7209635ffc03b35b
    http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_amd64.deb
    Size/MD5 checksum: 26394 847986887b14d0a038057478d2b30872

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_arm.deb
    Size/MD5 checksum: 46642 b0e4a64cf30e20dc069e3a57259235ce
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_arm.deb
    Size/MD5 checksum: 75798 b41386db73222899258e743a33c4f639
    http://security.debian.org/pool/updates/main/u/uw-imap/libc-client-dev_2002edebian1-13.1+etch1_arm.deb
    Size/MD5 checksum: 959814 d4589284f56b8e5746495c7ffb107a91
    http://security.debian.org/pool/updates/main/u/uw-imap/libc-client2002edebian_2002edebian1-13.1+etch1_arm.deb
    Size/MD5 checksum: 589126 91754725dff8d6cea245b24af8b963bb
    http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_arm.deb
    Size/MD5 checksum: 26082 fbe01ef72a463c603ee2802d5a83c863
    http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_arm.deb
    Size/MD5 checksum: 46566 f8e9a765ce2398f1361b2a3d23fc68ae

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/u/uw-imap/uw-mailutils_2002edebian1-13.1+etch1_hppa.deb
    Size/MD5 checksum: 49834 38e164bb266c4ac2b64efb1823520ad2
    http://security.debian.org/pool/updates/main/u/uw-imap/mlock_2002edebian1-13.1+etch1_hppa.deb
    Size/MD5 checksum: 26948 859538b21ee583afd0eae0fe23f5ccec
    http://security.debian.org/pool/updates/main/u/uw-imap/ipopd_2002edebian1-13.1+etch1_hppa.deb
    Size/MD5 checksum: 48276 fc635c859779ac21c7f3b5e1330ac96e
    http://security.debian.org/pool/updates/main/u/uw-imap/uw-imapd_2002edebian1-13.1+etch1_hppa.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
    • Michal Wronka
      Thu Jun 4 23:19:58 2026
      from Wroclaw, Poland via Telnet
    • Michal Wronka
      Thu Jun 4 23:17:20 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 145:12:28
    Calls: 12,089
    Calls today: 2
    Files: 15,000
    Messages: 6,517,496

© >>> Magnum BBS <<<, 2026