Bug#343836: Security: DoS attack possible - crashes on empty message

2005-12-21 Thread Martin Schulze
Matthias Andree wrote: > Martin Schulze wrote: > > > The patch does not apply though, since xfree() is unknown in version 6.2.5. > > I assume that the xfree only frees the memory when it is not NULL and sets > > the variable to NULL again, so the attached patch should do the same and > > apply >

Bug#343836: Security: DoS attack possible - crashes on empty message

2005-12-21 Thread Matthias Andree
Martin Schulze wrote: > The patch does not apply though, since xfree() is unknown in version 6.2.5. > I assume that the xfree only frees the memory when it is not NULL and sets > the variable to NULL again, so the attached patch should do the same and apply > to the version in Debian sarge/etch/si

Bug#343836: Security: DoS attack possible - crashes on empty message

2005-12-21 Thread Martin Schulze
Matthias Andree wrote: > are you using multidrop mode? If so, please test if the attached patch > fixes the bug. It is an untested backport from 6.3.1-rc1. > > If you are not using multidrop mode, please provide your configuration > details (passwords masked!) and a stack backtrace. Thanks a lot

Bug#343836: Security: DoS attack possible - crashes on empty message

2005-12-18 Thread Matthias Andree
tags 343836 + security thanks Steve, are you using multidrop mode? If so, please test if the attached patch fixes the bug. It is an untested backport from 6.3.1-rc1. If you are not using multidrop mode, please provide your configuration details (passwords masked!) and a stack backtrace. -- Ma

Bug#343836: Security: DoS attack possible - crashes on empty message

2005-12-17 Thread Steve Fosdick
Package: fetchmail Version: 6.2.5.4-1 Severity: important Wondering why only local mail had arrived in my mailbox for several days I found from the syslog that whenever fetchmail was started it got as far as message 46 from my ISPs POP3 server then crashed. I used telnet to log in to the POP3 ser