Eric S. Raymond Fetchmail Heap Corruption Vulnerability Solution:
Fetchmail 6.2.0 is not vulnerable to this issue. Users are advised to upgrade to the latest version of Fetchmail.
Gentoo Linux has released an advisory. Users who have installed net-mail/fetchmail-6.1.2 and earlier are urged to update their systems by issuing the following commands:
emerge rsync
emerge fetchmail
emerge clean
OpenPKG has released an advisory (OpenPKG-SA-2002.016) which addresses this issue. Fix information can be found in the attached advisory.
EnGarde Secure Linux has released a security advisory (ESA-20030127-002) which contains fixes. Users are urged to apply the supplied fixes as soon as possible.
Mandrake has released a security advisory (MDKSA-2003:011) containing fixes.
Immunix has released a security advisory (IMNX-2003-7+-023-01) including fixes.
Fixes are available:
Eric Raymond Fetchmail 5.3.3
Eric Raymond Fetchmail 5.4 .0
Eric Raymond Fetchmail 5.5
Eric Raymond Fetchmail 5.6
Eric Raymond Fetchmail 5.6.5
Eric Raymond Fetchmail 5.7
Eric Raymond Fetchmail 5.8 .0
Eric Raymond Fetchmail 5.9 .0
Eric Raymond Fetchmail 5.9.1
Eric Raymond Fetchmail 5.9.10
Eric Raymond Fetchmail 5.9.11
Eric Raymond Fetchmail 5.9.12
Eric Raymond Fetchmail 5.9.13
Eric Raymond Fetchmail 5.9.14
Eric Raymond Fetchmail 5.9.2
Eric Raymond Fetchmail 5.9.3
Eric Raymond Fetchmail 5.9.4
Eric Raymond Fetchmail 5.9.5
Eric Raymond Fetchmail 5.9.6
Eric Raymond Fetchmail 5.9.7
Eric Raymond Fetchmail 5.9.8
Eric Raymond Fetchmail 5.9.9
Eric Raymond Fetchmail 6.0 .0
Eric Raymond Fetchmail 6.1 .0
Eric Raymond Fetchmail 6.1.3