First published: Thu Feb 19 2009(Updated: )
The imap package provides server daemons for both the IMAP (Internet<br>Message Access Protocol) and POP (Post Office Protocol) mail access protocols.<br>A buffer overflow flaw was discovered in the dmail and tmail mail delivery<br>utilities shipped with imap. If either of these utilities were used as a<br>mail delivery agent, a remote attacker could potentially use this flaw to<br>run arbitrary code as the targeted user by sending a specially-crafted mail<br>message to the victim. (CVE-2008-5005)<br>Users of imap should upgrade to these updated packages, which contain a<br>backported patch to resolve this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2009:0275 is categorized as moderate.
To fix RHSA-2009:0275, you should update the imap package to the latest version provided by Red Hat.
RHSA-2009:0275 addresses a buffer overflow flaw in the dmail and tmail mail delivery utilities.
RHSA-2009:0275 affects the IMAP and POP mail access protocols provided by the imap package.
There is no specific workaround for RHSA-2009:0275, so upgrading is recommended.