[Fix] Openwebmail 1.71 remote root compromise

From: Dmitry Guyvoronsky (demiurg@altaee.com)
Date: 12/19/02

  • Next message: Damir Rajnovic: "Re: Cisco IOS EIGRP Network DoS"
    Date: Thu, 19 Dec 2002 18:55:06 +0200
    From: Dmitry Guyvoronsky <demiurg@altaee.com>
    To: bugtraq@securityfocus.com
    
    

    Hello

    Vendor of the OpenWebMail system had released patch and upgraded
    `current` sources.

    More information can be found at: http://sourceforge.net/forum/forum.php?thread_id=782605&forum_id=108435
    Patches: http://openwebmail.org/openwebmail/download/cert/patches/SA-02:01/
    Current: http://openwebmail.org/openwebmail/download/openwebmail-current.tgz

    -- 
    WBR Dmitry Guyvoronsky
    


    Relevant Pages

    • Re: The Register: OpenVMS among most-secure of operating systems
      ... The patch reaches the vendor, in this case the vendor of ... *without* it meaning that the vulnerability exists on VMS (nor does it ... > patches if the bug causes a problem on their OS. ... there have been many more BIND advisories ...
      (comp.os.vms)
    • Re: Maraudon Princess and Tinkerer
      ... > weapons were worth more than that to a vendor the head piece was only worth ... On my server it has become common practice to disenchant things noone ... with brilliant shards and they don't always fetch such a good price. ... vid consists of scenes shot from different patches. ...
      (alt.games.warcraft)
    • @stake advisory: HP dced Remote Command Execution Multiple OSes
      ... Vendor Status: Vendor has patches ... A buffer overflow vulnerability was discovered in HP's implementation ... HP-UX 11 with patches noted in bulletin HPSBUX0311-299 fixed this ... Common Vulnerabilities and Exposures (CVE) Information: ...
      (Bugtraq)
    • [VulnWatch] @stake: HP dced remote command execution multiple OSes
      ... Vendor Status: Vendor has patches ... CVE Candidate: ... A buffer overflow vulnerability was discovered in HP's implementation ... HP-UX 11 with patches noted in bulletin HPSBUX0311-299 fixed this ...
      (VulnWatch)
    • Re: Starting a new Enterprise Security Team
      ... Test every patch from every vendor. ... testing is up for debate; but what is not up for debate is whether any ... Software fix information and patches from giants like ... Microsoft and Dell may have some issues, but in my experience, software fix ...
      (microsoft.public.security)