|
From: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Date: Wed Sep 01 2004 - 11:30:46 EDT
-----BEGIN PGP SIGNED MESSAGE-----
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
vpopmail contains several bugs making it vulnerable to several SQL
Background
vpopmail handles virtual mail domains for qmail and Postfix.
Affected packages
-------------------------------------------------------------------
Description
vpopmail is vulnerable to several unspecified SQL injection exploits.
Impact
These vulnerabilities could allow an attacker to execute code with the
Workaround
There is no known workaround at this time. All users are encouraged to
Resolution
All vpopmail users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=net-mail/vpopmail-5.4.6"
References
[ 1 ] vpopmail Announcement
Availability
This GLSA and any updates to it are available for viewing at
http://security.gentoo.org/glsa/glsa-200409-01.xml
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the
License
Copyright 2004 Gentoo Foundation, Inc; referenced text
The contents of this document are licensed under the
http://creativecommons.org/licenses/by-sa/1.0
iD8DBQFBNesqzKC5hMHO6rkRAqQfAJ98vXJREfSCaCFHxtAjEvA/nqDnggCdGQYG
_______________________________________________
This archive was generated by hypermail 2.1.8 : Wed Sep 01 2004 - 13:01:15 EDT |
Custom Search
|