[14726] in bugtraq

home help back first fref pref prev next nref lref last post

Re: unsafe fgets() in qpopper

daemon@ATHENA.MIT.EDU (Qpopper Support)
Sun Apr 30 23:57:53 2000

Mime-Version: 1.0
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
Message-Id:  <p0432010fb52fff6c861a@[129.46.242.106]>
Date:         Fri, 28 Apr 2000 20:03:03 -0700
Reply-To: Qpopper Support <qpopper@QUALCOMM.COM>
From: Qpopper Support <qpopper@QUALCOMM.COM>
X-To:         Subscribers of Qpopper <qpopper@lists.pensive.org>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <109809596625226270179@lists.pensive.org>

This problem has been fixed in Qpopper 3.0.1b2, which is now available.

Note that the problem does not occur on Solaris systems (which use
Content-Length), nor  on systems which use mail or certain other
local delivery agents.  I was able to reproduce it on Linux using
mail.local.

Also, note that the patch supplied in the email message may not
function correctly and may cause messages to not be recognized.

home help back first fref pref prev next nref lref last post