SB2010082501 - Buffer overflow in alpine (Alpine package)
Published: August 25, 2010
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2008-5514)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=f293739e0db7bbddff5199f74b6150312c16a6cc
- https://git.alpinelinux.org/aports/commit/?id=ec56c6104f84980b4387dd935c47ca94cdd468c8
- https://git.alpinelinux.org/aports/commit/?id=73cbf1b72f817d729386d4eca4118ffd551f373c
- https://git.alpinelinux.org/aports/commit/?id=c38e2a8013d5b57d6c89d6e9dbc2b6e496618b52
- https://git.alpinelinux.org/aports/commit/?id=ba489c5e19754da1c71031b7c462b9614518d2ef
- https://git.alpinelinux.org/aports/commit/?id=ad70614b79945bf2bed296b6ad737bc871609a1c