[Subject Prev][Subject Next][Thread Prev][Thread Next][Subject Index][Thread Index]

(fwd) Qpopper 4.0.3 **** Fixes Buffer Overflow **** (fwd)



[Qpopper 4.0.x where x < 3 has a buffer overflow.  If you use Qpopper
please upgrade, from source or as soon as your distribution vendor
releases a package for 4.0.3 -- Raju]

This is an RFC 1153 digest.
(1 message)
----------------------------------------------------------------------

Return-Path: <bugtraq-return-244-raju=linux-delhi.org@xxxxxxxxxxxxxxxxx>
Mailing-List: contact bugtraq-help@xxxxxxxxxxxxxxxxx; run by ezmlm
Precedence: bulk
List-Id: <bugtraq.list-id.securityfocus.com>
List-Post: <mailto:bugtraq@xxxxxxxxxxxxxxxxx>
List-Help: <mailto:bugtraq-help@xxxxxxxxxxxxxxxxx>
List-Unsubscribe: <mailto:bugtraq-unsubscribe@xxxxxxxxxxxxxxxxx>
List-Subscribe: <mailto:bugtraq-subscribe@xxxxxxxxxxxxxxxxx>
Delivered-To: mailing list bugtraq@xxxxxxxxxxxxxxxxx
Delivered-To: moderator for bugtraq@xxxxxxxxxxxxxxxxx
Received: (qmail 29768 invoked from network); 2 Jun 2001 15:38:37 -0000
Message-ID: <Pine.LNX.4.30.0106021037100.19348-100000@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
From: Michael Brennen <mbrennen@xxxxxxx>
To: <bugtraq@xxxxxxxxxxxxxxxxx>
Subject: Qpopper 4.0.3 **** Fixes Buffer Overflow **** (fwd)
Date: Sat, 2 Jun 2001 10:37:44 -0500 (CDT)


Forwarded from the qpopper list.

---------- Forwarded message ----------
Date: Fri, 1 Jun 2001 23:28:20 -0700
From: Qpopper Support <qpopper@xxxxxxxxxxxx>
To: Qpopper Public List <qpopper@xxxxxxxxxxxxxxxxx>,
     qpopper-announce@xxxxxxxxxxxxxxxxxx
Cc: qpopper@xxxxxxxxxxxx
Subject: Qpopper 4.0.3 **** Fixes Buffer Overflow ****

Qpopper 4.0.3 is available at
<ftp://ftp.qualcomm.com/eudora/servers/unix/popper/>.


**** 4.0.3 FIXES A BUFFER OVERFLOW PRESENT IN ALL VERSIONS OF 4.0 --
PLEASE UPGRADE IMMEDIATELY ***


Changes from 4.0.2 to 4.0.3:
----------------------------
  1.  Don't call SSL_shutdown unless we tried to negotiate an
      SSL session.  (As suggested by Kenneth Porter.)
  2.  Fix buffer overflow  (reported by Gustavo Viscaino).
  3.  Fixed empty password treated as empty command (patch
      submitted by Michael Smith and others).
  4.  Added patch by Carles Xavier Munyoz to fix erroneous
      scanning for \n in getline().
  5.  Fix from Arvin Schnell for warnings on 64-bit systems.
  6.  Added patch by Clifton Royston to change error message
      for nonauthfile and authfile tests.
  7.  Added 'uw-kludge' as synonym for 'uw-kluge'.

------------------------------

End of this Digest
******************

-- 
Raju Mathur          raju@xxxxxxxxxxxxx           http://kandalaya.org/