Imapd 远程缓冲溢出漏洞

漏洞信息详情

Imapd 远程缓冲溢出漏洞

漏洞简介

CVE(CAN) ID: CAN-2001-0691

Washington University Imapd 是一个流行的服务器程序,它使用户通过IMAP协议直接

从服务器下载邮件。

发现Imapd存在多个缓冲溢出漏洞,如果用户已经通过认证,就可能远程远程获得

shell权限。

这个漏洞影响那些只开放email访问权限的系统,对于已经提供shell访问权限的系

统,这个漏洞并不能给攻击者任何特权。

漏洞公告

厂商补丁:

Linux-Mandrake (
http://www.linux-mandrake.com/en/security/
)为此发布了一份安全公告 :

MDKSA-2001:054 – imap update

补丁下载 –

________________________________________________________________________

Linux-Mandrake 7.1:

6bf29864715e9a7fcfca87fcbba9774f 7.1/RPMS/imap-2000c-4.6mdk.i586.rpm

a0868dc57cf7ce8a39baeba197d44132 7.1/RPMS/imap-devel-2000c-4.6mdk.i586.rpm

e574413ee56c8a30bcc907e4a3042eac 7.1/SRPMS/imap-2000c-4.6mdk.src.rpm

Linux-Mandrake 7.2:

84255f2e48d8941a9ebfc9b96aa29485 7.2/RPMS/imap-2000c-4.5mdk.i586.rpm

641bb3f1c7a89d21826074a24f1f480f 7.2/RPMS/imap-devel-2000c-4.5mdk.i586.rpm

0e123cce424178305fb86e739c198734 7.2/SRPMS/imap-2000c-4.5mdk.src.rpm

Mandrake Linux 8.0:

6a452cc1dc11d0b4e463bad8ad72c76f 8.0/RPMS/imap-2000c-4.4mdk.i586.rpm

b5e240934dce233b30b3b9b3dd378548 8.0/RPMS/imap-devel-2000c-4.4mdk.i586.rpm

7e3c70c61268f0cc2ee129d17e363897 8.0/SRPMS/imap-2000c-4.4mdk.src.rpm

Corporate Server 1.0.1:

6bf29864715e9a7fcfca87fcbba9774f 1.0.1/RPMS/imap-2000c-4.6mdk.i586.rpm

a0868dc57cf7ce8a39baeba197d44132 1.0.1/RPMS/imap-devel-2000c-4.6mdk.i586.rpm

e574413ee56c8a30bcc907e4a3042eac 1.0.1/SRPMS/imap-2000c-4.6mdk.src.rpm

下载站点列表:


http://www.linux-mandrake.com/en/ftp.php3

________________________________________________________________________

参考网址

来源: BID
名称: 2856
链接:http://www.securityfocus.com/bid/2856

来源: MANDRAKE
名称: MDKSA-2001:054
链接:http://www.securityfocus.com/advisories/3352

来源: REDHAT
名称: RHSA-2001:094
链接:http://www.redhat.com/support/errata/RHSA-2001-094.html

来源: XF
名称: imap-ipop2d-ipop3d-bo(6269)
链接:http://www.iss.net/security_center/static/6269.php

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享