RHSA-2009:0275: Moderate: imap security update
The imap package provides server daemons for both the IMAP (InternetMessage Access Protocol) and POP (Post Office Protocol) mail access protocols.A buffer overflow flaw was discovered in the dmail and tmail mail deliveryutilities shipped with imap. If either of these utilities were used as amail delivery agent, a remote attacker could potentially use this flaw torun arbitrary code as the targeted user by sending a specially-crafted mailmessage to the victim. (CVE-2008-5005)Users of imap should upgrade to these updated packages, which contain abackported patch to resolve this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:0275?
The severity of RHSA-2009:0275 is categorized as moderate.
How do I fix RHSA-2009:0275?
To fix RHSA-2009:0275, you should update the imap package to the latest version provided by Red Hat.
What is the nature of the flaw in RHSA-2009:0275?
RHSA-2009:0275 addresses a buffer overflow flaw in the dmail and tmail mail delivery utilities.
What services are affected by RHSA-2009:0275?
RHSA-2009:0275 affects the IMAP and POP mail access protocols provided by the imap package.
Is there a workaround for RHSA-2009:0275?
There is no specific workaround for RHSA-2009:0275, so upgrading is recommended.