Oval Definition:oval:com.redhat.rhsa:def:20070385
Revision Date:2007-06-07Version:637
Title:RHSA-2007:0385: fetchmail security update (Moderate)
Description:Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections.

  • A flaw was found in the way fetchmail processed certain APOP authentication requests. By sending certain responses when fetchmail attempted to authenticate against an APOP server, a remote attacker could potentially acquire certain portions of a user's authentication credentials. (CVE-2007-1558)

    All users of fetchmail should upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-1558
    RHSA-2007:0385
    RHSA-2007:0385-03
    RHSA-2007:0385-03
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND fetchmail is earlier than 0:6.2.0-3.el3.4
  • AND fetchmail is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND fetchmail is earlier than 0:6.2.5-6.0.1.el4
  • AND fetchmail is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND fetchmail is earlier than 0:6.3.6-1.0.1.el5
  • AND fetchmail is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND fetchmail is earlier than 0:6.2.0-3.el3.4
  • AND fetchmail is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND fetchmail is earlier than 0:6.2.5-6.0.1.el4
  • AND fetchmail is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND fetchmail is earlier than 0:6.3.6-1.0.1.el5
  • AND fetchmail is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND fetchmail is earlier than 0:6.2.5-6.0.1.el4
  • AND fetchmail is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND fetchmail is earlier than 0:6.3.6-1.0.1.el5
  • AND fetchmail is signed with Red Hat redhatrelease2 key
  • BACK