Bug#348407: pine: security hole in imap support

2006-01-18 Thread Moritz Muehlenhoff
Santiago Vila wrote: > How exactly this is dangerous in *pine*? (not in the IMAP server) The problem is that we have another case of an embedded code copy, something we should get rid of for Etch for as many packages as possible. > You gain access to the system if you are running pine? That would

Bug#348407: pine: security hole in imap support

2006-01-17 Thread Stephen Gran
This one time, at band camp, Santiago Vila said: > On Mon, 16 Jan 2006, Will Lowe wrote: > > > Package: pine > > Version: 4.62-1 > > Severity: grave > > Justification: user security hole > > > > http://www.washington.edu/pine/ says: > > > > Note: Install Pine 4.64, or later version, to fix a buf

Bug#348407: pine: security hole in imap support

2006-01-17 Thread Will Lowe
I believe that a mailicious IMAP server can gain access to the local system (where Pine is running). Agree that non-free sucks, but wanted to point the problem out since I'm sure a lot of folks are using our pine and pine-tracker packages. On Wed, Jan 18, 2006 at 02:04:53AM +0100, Santiago Vila w

Bug#348407: pine: security hole in imap support

2006-01-17 Thread Santiago Vila
On Mon, 16 Jan 2006, Will Lowe wrote: > Package: pine > Version: 4.62-1 > Severity: grave > Justification: user security hole > > http://www.washington.edu/pine/ says: > > Note: Install Pine 4.64, or later version, to fix a buffer overflow > problem. Read iDEFENSE Security Advisory for full deta

Bug#348407: pine: security hole in imap support

2006-01-16 Thread Will Lowe
Package: pine Version: 4.62-1 Severity: grave Justification: user security hole http://www.washington.edu/pine/ says: Note: Install Pine 4.64, or later version, to fix a buffer overflow problem. Read iDEFENSE Security Advisory for full details. The advisory is here: http://www.idefense.com/inte