copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-98.116 -- Red Hat Linux Bulletin -- SECURITY: imap-4.1.final now available

Date: 20 July 1998

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----

===========================================================================
            AUSCERT External Security Bulletin Redistribution
                                    
                                    
                  ESB-98.116 -- Red Hat Linux Bulletin
                 SECURITY: imap-4.1.final now available
                              20 July 1998

===========================================================================

Red Hat Software, Inc. has released the following advisory concerning
security problems found in all versions of imap shipped with Red Hat Linux.

The following security bulletin is provided as a service to AusCERT's
members.  As AusCERT did not write this document, AusCERT has had no
control over its content.  As such, the decision to use any or all of this
information is the responsibility of each user or organisation, and should
be done so in accordance with site policies and procedures.

NOTE: This is only the original release of the security bulletin.  It will
not be updated when the original bulletin is.  If downloading at a later
date, it is recommended that the bulletin is retrieved from the original
authors to ensure that the information is still current.

If you have any questions or need further information, please contact 
Red Hat Software directly.

Previous advisories and external security bulletins can be retrieved from:

	http://www.auscert.org.au/Information/advisories.html

If you believe that your system has been compromised, contact AusCERT or
your representative in FIRST (Forum of Incident Response and Security
Teams).

Internet Email: auscert@auscert.org.au
Facsimile:	(07) 3365 7031
Telephone:	(07) 3365 4417 (International: +61 7 3365 4417)
		AusCERT personnel answer during Queensland business hours
		which are GMT+10:00 (AEST).
		On call after hours for emergencies.


- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----


There was a mistake in the original post about the imap update. Red Hat's
default /etc/inetd.conf does enable imap by default; if "rpm -q imap"
succeeds (i.e. says something other then "package imap is not installed")
you are vulnerable to this problem. A corrected announcement follows.

Thanks to Donnie Barnes for pointing out that I'm a fool.

Erik

- - ----

Serious security problems have been found in all versions of imap shipped
with Red Hat Linux. If "rpm -q imap" shows that imap is installed on
your system, please upgrade to these new imap releases immediately, or
remove imap by running "rpm -e imap". Note that Red Hat's imap package
also provides a POP server, so only remove it if you don't need to provide
POP services.

Thanks to everyone who helped find these problem, Olaf Kirch in particular.

Red Hat 5.0 and 5.1
- - - -------------------

i386:
rpm -Uvh ftp://ftp.redhat.com/updates/5.0/i386/imap-4.1.final-1.i386.rpm

alpha:
rpm -Uvh ftp://ftp.redhat.com/updates/5.0/alpha/imap-4.1.final-1.alpha.rpm

SPARC:
rpm -Uvh ftp://ftp.redhat.com/updates/5.0/sparc/imap-4.1.final-1.sparc.rpm

Red Hat 4.2
- - - -------------

i386:
rpm -Uvh ftp://ftp.redhat.com/updates/4.2/i386/imap-4.1.final-0.i386.rpm

alpha:
rpm -Uvh ftp://ftp.redhat.com/updates/4.2/alpha/imap-4.1.final-0.alpha.rpm

SPARC:
rpm -Uvh ftp://ftp.redhat.com/updates/4.2/sparc/imap-4.1.final-0.sparc.rpm

- -----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBNa6tTaUg6PHLopv5AQHAAwP/ab8o0Qi56AuANrKy0bGiuPyev2hoWm26
8ooO5yQxs0NhFI4Ff7MZn89AjvjTwTPsIFQdIVTRbATpCGi7GYor4o41NqnrQDlp
24eWLXNW7DIZ7+TFbDA79gws+TMgDhfueoYFE4KvJ0xj1q2I4D5gN09MXF9x8UCe
ENhEvIzTCL8=
=wCOg
- -----END PGP SIGNATURE-----

- ---------------------------END INCLUDED TEXT---------------------

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key

iQCVAwUBNbX2JSh9+71yA2DNAQHbGQP/S47jZM8PU1ZWZd8wBD9v1cSIhHWlAS34
kAjlgUuVctw6jWM/EmkFH79xlQ73fIKovxkBrVLpiaIT20fvoB7hQ/fG4rpAXpeM
pDpuqKQYCiVW4MoDrlZwJMMk/4ZMiAP3KaOM2VPJMonuj1u8b5lXN1F9LhAAYmzl
pVjSAD1cXdM=
=btji
-----END PGP SIGNATURE-----