GLSA: balsa (200304-10)

From: Daniel Ahlberg (alizat_private)
Date: Wed Apr 30 2003 - 06:40:25 PDT

  • Next message: Marco Ivaldi: "[Full-Disclosure] OpenSSH/PAM timing attack allows remote users identification"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200304-10
    - - - ---------------------------------------------------------------------
    
              PACKAGE : balsa
              SUMMARY : buffer overflow
                 DATE : 2003-04-30 13:40 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : <balsa-2.0.10
        FIXED VERSION : >=balsa-2.0.10
                  CVE : CAN-2003-0140
    
    - - - ---------------------------------------------------------------------
    
    Balsa suffers from the same buffer overflow as mutt did:
    
    http://marc.theaimsgroup.com/?l=bugtraq&m=104852190605988&w=2
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    net-mail/balsa upgrade to balsa-2.0.10 as follows:
    
    emerge sync
    emerge balsa
    emerge clean
    
    - - - ---------------------------------------------------------------------
    alizat_private - GnuPG key is available at http://cvs.gentoo.org/~aliz
    - - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)
    
    iD8DBQE+r9JFfT7nyhUpoZMRAsdKAJ9I0a0slAseBKANge+YWNEVSQ1d3wCdHwOv
    9Sk4vDxSc0dZ7zQqpSRIJYo=
    =JBzV
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Wed Apr 30 2003 - 08:08:23 PDT