GLSA: balsa (200304-10)

From: Daniel Ahlberg (aliz_at_gentoo.org)
Date: 04/30/03

  • Next message: Cisco Systems Product Security Incident Response Team: "Cisco Security Advisory: Cisco Content Service Switch 11000 Series DNS Negative Cache of Information Denial-of-Service"
    Date: Wed, 30 Apr 2003 15:40:25 +0200
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200304-10
    - - - ---------------------------------------------------------------------

              PACKAGE : balsa
              SUMMARY : buffer overflow
                 DATE : 2003-04-30 13:40 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : <balsa-2.0.10
        FIXED VERSION : >=balsa-2.0.10
                  CVE : CAN-2003-0140

    - - - ---------------------------------------------------------------------

    Balsa suffers from the same buffer overflow as mutt did:

    http://marc.theaimsgroup.com/?l=bugtraq&m=104852190605988&w=2

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    net-mail/balsa upgrade to balsa-2.0.10 as follows:

    emerge sync
    emerge balsa
    emerge clean

    - - - ---------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
    - - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)

    iD8DBQE+r9JFfT7nyhUpoZMRAsdKAJ9I0a0slAseBKANge+YWNEVSQ1d3wCdHwOv
    9Sk4vDxSc0dZ7zQqpSRIJYo=
    =JBzV
    -----END PGP SIGNATURE-----


  • Next message: Cisco Systems Product Security Incident Response Team: "Cisco Security Advisory: Cisco Content Service Switch 11000 Series DNS Negative Cache of Information Denial-of-Service"

    Relevant Pages

    • [Full-Disclosure] GLSA: balsa (200304-10)
      ... Balsa suffers from the same buffer overflow as mutt did: ... It is recommended that all Gentoo Linux users who are running ... emerge balsa ... aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: openssh (200309-11)
      ... read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge openssh ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: pam_smb (200309-01)
      ... "If a long password is supplied, this can cause a buffer overflow which ... It is recommended that all Gentoo Linux users who are running ... emerge pam_smb ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: pam_smb (200309-01)
      ... "If a long password is supplied, this can cause a buffer overflow which ... It is recommended that all Gentoo Linux users who are running ... emerge pam_smb ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: pam_smb (200309-01)
      ... "If a long password is supplied, this can cause a buffer overflow which ... It is recommended that all Gentoo Linux users who are running ... emerge pam_smb ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
      (Full-Disclosure)