Summary
Ubuntu Update for Linux kernel vulnerabilities USN-520-1
Solution
Please Install the Updated Packages.
Insight
Gaetan Leurent discovered a vulnerability in the APOP protocol based on MD5 collisions. As fetchmail supports the APOP protocol, this vulnerability can be used by attackers to discover a portion of the APOP user's authentication credentials. (CVE-2007-1558)
Earl Chew discovered that fetchmail can be made to de-reference a NULL pointer when contacting SMTP servers. This vulnerability can be used by attackers who control the SMTP server to crash fetchmail and cause a denial of service. (CVE-2007-4565)
Affected
fetchmail vulnerabilities on Ubuntu 6.06 LTS ,
Ubuntu 6.10 ,
Ubuntu 7.04
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2007-1558, CVE-2007-4565 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities