fetchmail denial of service in multibyte locales

Bug #566636 reported by Matthias Andree
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
fetchmail (Ubuntu)
Fix Released
Undecided
Unassigned
Nominated for Dapper by Matthias Andree
Nominated for Hardy by Matthias Andree
Nominated for Intrepid by Matthias Andree
Nominated for Jaunty by Matthias Andree
Nominated for Karmic by Matthias Andree
Nominated for Lucid by Matthias Andree

Bug Description

Binary package hint: fetchmail

This is a draft of an upstream security announcement for fetchmail that also affects all versions ever shipped by Ubuntu, to be publicly released once the CVE name has been assigned (it is not yet, and has been requested via oss-security@).

Fixing this for Lucid should be highest priority, even before fixing shipping/supported releases such as Karmic.

http://gitorious.org/fetchmail/fetchmail/blobs/raw/master/fetchmail-SA-2010-02.txt (attached).

NOTE: The patch from the SA WILL NOT YIELD a working fetchmail copy in Ubuntu, because the base fetchmail version is older than 6.3.14.

This is also a showcase for the issue described in https://bugs.launchpad.net/ubuntu/+source/fetchmail/+bug/557467 that upgrading outdated packages will become ever harder over time.

Tags: patch

CVE References

Revision history for this message
Matthias Andree (matthias-andree) wrote :

The information is public already, no need to keep the Ubuntu copy private.

visibility: private → public
Changed in fetchmail (Ubuntu):
status: New → Confirmed
Revision history for this message
Matthias Andree (matthias-andree) wrote :

Can someone make this visible in the Lucid release series and assign an appropriate Importance please? Else it may be missed for 10.04 - and you don't want to ship vulnerable code, do you?

Revision history for this message
Matthias Andree (matthias-andree) wrote :

Note that I've had to change the patch as it missed one place in the code. I've reuploaded the new security announcement.

tags: added: patch
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

This was fixed in 6.3.17-4ubuntu1.

Changed in fetchmail (Ubuntu):
status: Confirmed → Fix Released
Revision history for this message
Matthias Andree (matthias-andree) wrote :

wow, only three hours and one year (!) after the SA. :-( Seriously, this response time needs to improve massively.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

@Matthias: this was fixed a long time ago-- only the bug didn't get updated until yesterday.

Revision history for this message
Matthias Andree (matthias-andree) wrote :

Sorry for the misunderstanding.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.