|
Mandriva- Advisories MDKSA-2007:113: Updated mutt packages fix vulnerabilities
Advisories MDKSA-2007:113: Updated mutt packages fix vulnerabilities
A flaw in the way mutt processed certain APOP authentication requests was discovered. By sending certain responses when mutt attempted to authenticate again an APOP server, a remote attacker could possibly obtain certain portions of the user's authentication credentials (CVE-2007-1558). A flaw in how mutt handled certain characters in gecos fields could lead to a buffer overflow. A local user able to give themselves a carefully crafted Real Name could potentially execute arbitrary code if a victim used mutt to expand the attacker's alias (CVE-2007-2683). Updated packages have been patched to address these issues.
http://mandrivausers.org/index.php?showtopic=41941
Array
Mon, 04 Jun 2007 23:58:34 +0000
|