セキュリティのバグを修正したfetchmailのアップデートパッケージがRed Hat Enterprise Linux 2.1、3、4、および5で利用可能になりました。
このアップデートは、レッドハットセキュリティ対策チームによって、深刻度「中(Moderate)」のセキュリティ問題と評価されています。
fetchmailは、SLIP接続やPPP接続といったオンデマンドのTCP/IPリンクで使用できるリモートメール取得/転送ユーティリティです。
fetchmailでの特定のAPOP認証要求の処理で欠陥が見つかりました。fetchmailがAPOPサーバに対して認証を試みたときに特定の応答を送信することによって、リモート攻撃者がユーザの認証証明書の特定部分を取得することが可能です。(CVE-2007-1558)
fetchmailのすべてのユーザは、この問題を修正するバックポートパッチを含む上記アップデートパッケージにアップグレードしてください。
| RHEL Desktop Workstation (v. 5 client) | |
| SRPMS: | |
| fetchmail-6.3.6-1.0.1.el5.src.rpm | 666e02a914664774f345ecac40559a2d |
| IA-32: | |
| fetchmail-6.3.6-1.0.1.el5.i386.rpm | 375d0b1208f2bd7d5cc2b353af1f946e |
| x86_64: | |
| fetchmail-6.3.6-1.0.1.el5.x86_64.rpm | 949bbf662673a20466b8bf3cffdc67f0 |
| Red Hat Desktop (v. 3) | |
| SRPMS: | |
| fetchmail-6.2.0-3.el3.4.src.rpm | e4049e8c0c6ea283c381316505f68c75 |
| IA-32: | |
| fetchmail-6.2.0-3.el3.4.i386.rpm | cd26bbf307cb7536e9174bbb7ff41b71 |
| x86_64: | |
| fetchmail-6.2.0-3.el3.4.x86_64.rpm | ec359701cb914c721eb657cf95281e4d |
| Red Hat Desktop (v. 4) | |
| SRPMS: | |
| fetchmail-6.2.5-6.0.1.el4.src.rpm | 3e44a39b1953a94a0d0bc5d9350c3f19 |
| IA-32: | |
| fetchmail-6.2.5-6.0.1.el4.i386.rpm | 6857913fd4ef4e820ca569e63e6b6043 |
| x86_64: | |
| fetchmail-6.2.5-6.0.1.el4.x86_64.rpm | 42938e325c512f22a0385168a64d0a02 |
| Red Hat Enterprise Linux (v. 5 server) | |
| SRPMS: | |
| fetchmail-6.3.6-1.0.1.el5.src.rpm | 666e02a914664774f345ecac40559a2d |
| IA-32: | |
| fetchmail-6.3.6-1.0.1.el5.i386.rpm | 375d0b1208f2bd7d5cc2b353af1f946e |
| IA-64: | |
| fetchmail-6.3.6-1.0.1.el5.ia64.rpm | 25793651de52f19a1577f76c8a21f326 |
| PPC: | |
| fetchmail-6.3.6-1.0.1.el5.ppc.rpm | b6e301472f65451199ffce4f806dad61 |
| s390x: | |
| fetchmail-6.3.6-1.0.1.el5.s390x.rpm | 2e21162b1d4df12524ce2362c98895bb |
| x86_64: | |
| fetchmail-6.3.6-1.0.1.el5.x86_64.rpm | 949bbf662673a20466b8bf3cffdc67f0 |
| Red Hat Enterprise Linux AS (v. 2.1) | |
| SRPMS: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.src.rpm | 117edccd5352db96a61b676bcaa01ae6 |
| IA-32: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.i386.rpm | 728c7b146503801d0fc808c897987e94 |
| fetchmailconf-5.9.0-21.7.3.el2.1.6.i386.rpm | 1522beaa934b30cdc4bdad88e7bbe050 |
| IA-64: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.ia64.rpm | 533657a336cf0e823c72027154f4617d |
| fetchmailconf-5.9.0-21.7.3.el2.1.6.ia64.rpm | e6b8e4a0bbc86888b81abb9621c64ea4 |
| Red Hat Enterprise Linux AS (v. 3) | |
| SRPMS: | |
| fetchmail-6.2.0-3.el3.4.src.rpm | e4049e8c0c6ea283c381316505f68c75 |
| IA-32: | |
| fetchmail-6.2.0-3.el3.4.i386.rpm | cd26bbf307cb7536e9174bbb7ff41b71 |
| IA-64: | |
| fetchmail-6.2.0-3.el3.4.ia64.rpm | 593597ab7bc9c98d4cd77791ce22b885 |
| PPC: | |
| fetchmail-6.2.0-3.el3.4.ppc.rpm | 0de4e90b14b10d71221180193d8112df |
| s390: | |
| fetchmail-6.2.0-3.el3.4.s390.rpm | 82d7535a6c060c044abdcc35258cd9f6 |
| s390x: | |
| fetchmail-6.2.0-3.el3.4.s390x.rpm | fe85674a73ed2c5e11a38d58c3d52c31 |
| x86_64: | |
| fetchmail-6.2.0-3.el3.4.x86_64.rpm | ec359701cb914c721eb657cf95281e4d |
| Red Hat Enterprise Linux AS (v. 4) | |
| SRPMS: | |
| fetchmail-6.2.5-6.0.1.el4.src.rpm | 3e44a39b1953a94a0d0bc5d9350c3f19 |
| IA-32: | |
| fetchmail-6.2.5-6.0.1.el4.i386.rpm | 6857913fd4ef4e820ca569e63e6b6043 |
| IA-64: | |
| fetchmail-6.2.5-6.0.1.el4.ia64.rpm | f3684335eb952d359ac12db780fb48f2 |
| PPC: | |
| fetchmail-6.2.5-6.0.1.el4.ppc.rpm | b36cbb25c342f85070f2d90f7de02646 |
| s390: | |
| fetchmail-6.2.5-6.0.1.el4.s390.rpm | 4ea73c34d4500f1c9fbc28175f0ede18 |
| s390x: | |
| fetchmail-6.2.5-6.0.1.el4.s390x.rpm | 12e753c255e6e2da2d02105631d0302e |
| x86_64: | |
| fetchmail-6.2.5-6.0.1.el4.x86_64.rpm | 42938e325c512f22a0385168a64d0a02 |
| Red Hat Enterprise Linux ES (v. 2.1) | |
| SRPMS: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.src.rpm | 117edccd5352db96a61b676bcaa01ae6 |
| IA-32: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.i386.rpm | 728c7b146503801d0fc808c897987e94 |
| fetchmailconf-5.9.0-21.7.3.el2.1.6.i386.rpm | 1522beaa934b30cdc4bdad88e7bbe050 |
| Red Hat Enterprise Linux ES (v. 3) | |
| SRPMS: | |
| fetchmail-6.2.0-3.el3.4.src.rpm | e4049e8c0c6ea283c381316505f68c75 |
| IA-32: | |
| fetchmail-6.2.0-3.el3.4.i386.rpm | cd26bbf307cb7536e9174bbb7ff41b71 |
| IA-64: | |
| fetchmail-6.2.0-3.el3.4.ia64.rpm | 593597ab7bc9c98d4cd77791ce22b885 |
| x86_64: | |
| fetchmail-6.2.0-3.el3.4.x86_64.rpm | ec359701cb914c721eb657cf95281e4d |
| Red Hat Enterprise Linux ES (v. 4) | |
| SRPMS: | |
| fetchmail-6.2.5-6.0.1.el4.src.rpm | 3e44a39b1953a94a0d0bc5d9350c3f19 |
| IA-32: | |
| fetchmail-6.2.5-6.0.1.el4.i386.rpm | 6857913fd4ef4e820ca569e63e6b6043 |
| IA-64: | |
| fetchmail-6.2.5-6.0.1.el4.ia64.rpm | f3684335eb952d359ac12db780fb48f2 |
| x86_64: | |
| fetchmail-6.2.5-6.0.1.el4.x86_64.rpm | 42938e325c512f22a0385168a64d0a02 |
| Red Hat Enterprise Linux WS (v. 2.1) | |
| SRPMS: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.src.rpm | 117edccd5352db96a61b676bcaa01ae6 |
| IA-32: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.i386.rpm | 728c7b146503801d0fc808c897987e94 |
| fetchmailconf-5.9.0-21.7.3.el2.1.6.i386.rpm | 1522beaa934b30cdc4bdad88e7bbe050 |
| Red Hat Enterprise Linux WS (v. 3) | |
| SRPMS: | |
| fetchmail-6.2.0-3.el3.4.src.rpm | e4049e8c0c6ea283c381316505f68c75 |
| IA-32: | |
| fetchmail-6.2.0-3.el3.4.i386.rpm | cd26bbf307cb7536e9174bbb7ff41b71 |
| IA-64: | |
| fetchmail-6.2.0-3.el3.4.ia64.rpm | 593597ab7bc9c98d4cd77791ce22b885 |
| x86_64: | |
| fetchmail-6.2.0-3.el3.4.x86_64.rpm | ec359701cb914c721eb657cf95281e4d |
| Red Hat Enterprise Linux WS (v. 4) | |
| SRPMS: | |
| fetchmail-6.2.5-6.0.1.el4.src.rpm | 3e44a39b1953a94a0d0bc5d9350c3f19 |
| IA-32: | |
| fetchmail-6.2.5-6.0.1.el4.i386.rpm | 6857913fd4ef4e820ca569e63e6b6043 |
| IA-64: | |
| fetchmail-6.2.5-6.0.1.el4.ia64.rpm | f3684335eb952d359ac12db780fb48f2 |
| x86_64: | |
| fetchmail-6.2.5-6.0.1.el4.x86_64.rpm | 42938e325c512f22a0385168a64d0a02 |
| Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor | |
| SRPMS: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.src.rpm | 117edccd5352db96a61b676bcaa01ae6 |
| IA-64: | |
| fetchmail-5.9.0-21.7.3.el2.1.6.ia64.rpm | 533657a336cf0e823c72027154f4617d |
| fetchmailconf-5.9.0-21.7.3.el2.1.6.ia64.rpm | e6b8e4a0bbc86888b81abb9621c64ea4 |
| (The unlinked packages above are only available from the Red Hat Network) | |
241191 - CVE-2007-1558 fetchmail, mutt: APOP vulnerability
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/