Summary
The remote host is missing an update to fetchmail
announced via advisory DSA 1377-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201377-1
Insight
Matthias Andree discovered that fetchmail, an SSL enabled POP3, APOP and IMAP mail gatherer/forwarder, can under certain circumstances attempt to dereference a NULL pointer and crash.
For the stable distribution (etch), this problem has been fixed in version 6.3.6-1etch1.
For the old stable distribution (sarge), this problem was not present.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your fetchmail package.
Severity
Classification
-
CVE CVE-2007-4565 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities