CVE-2007-1558
published 2007-04-16CVE-2007-1558: The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and…
PriorityP412low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
2.42%
82.3th percentile
The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| claws-mail | claws-mail | >= 0 < 2.9.1-1 | 2.9.1-1 |
| claws-mail | claws-mail | >= 0 < 2.9.1-1 | 2.9.1-1 |
| claws-mail | claws-mail | >= 0 < 2.9.1-1 | 2.9.1-1 |
| claws-mail | claws-mail | >= 0 < 2.9.1-1 | 2.9.1-1 |
| debian | balsa | < balsa 2.3.17-1 (bookworm) | balsa 2.3.17-1 (bookworm) |
| debian | claws-mail | < balsa 2.3.17-1 (bookworm) | balsa 2.3.17-1 (bookworm) |
| debian | fetchmail | < balsa 2.3.17-1 (bookworm) | balsa 2.3.17-1 (bookworm) |
| debian | mailfilter | < balsa 2.3.17-1 (bookworm) | balsa 2.3.17-1 (bookworm) |
| debian | mutt | < balsa 2.3.17-1 (bookworm) | balsa 2.3.17-1 (bookworm) |
| fetchmail | fetchmail | >= 0 < 6.3.8-1 | 6.3.8-1 |
| fetchmail | fetchmail | >= 0 < 6.3.8-1 | 6.3.8-1 |
| fetchmail | fetchmail | >= 0 < 6.3.8-1 | 6.3.8-1 |
| gnome | balsa | >= 0 < 2.3.17-1 | 2.3.17-1 |
| gnome | balsa | >= 0 < 2.3.17-1 | 2.3.17-1 |
| gnome | balsa | >= 0 < 2.3.17-1 | 2.3.17-1 |
| gnome | balsa | >= 0 < 2.3.17-1 | 2.3.17-1 |
| mutt | mutt | >= 0 < 1.5.18-6 | 1.5.18-6 |
| mutt | mutt | >= 0 < 1.5.18-6 | 1.5.18-6 |
| mutt | mutt | >= 0 < 1.5.18-6 | 1.5.18-6 |
| mutt | mutt | >= 0 < 1.5.18-6 | 1.5.18-6 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jmh6-7c53-fg26: The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message
ghsa_unreviewed·2022-05-03
CVE-2007-1558 [LOW] GHSA-jmh6-7c53-fg26: The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message
The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.
OSV
CVE-2007-1558: The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message
osv·2007-04-16·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558: The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message
The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.
Ubuntu
fetchmail vulnerabilities
vendor_ubuntu·2007-09-26·CVSS 2.6
CVE-2007-1558 [LOW] fetchmail vulnerabilities
Title: fetchmail vulnerabilities
Summary: fetchmail vulnerabilities
Gaetan Leurent discovered a vulnerability in the APOP protocol based
on MD5 collisions. As fetchmail supports the APOP protocol, this
vulnerability can be used by attackers to discover a portion of the APOP
user's authentication credentials. (CVE-2007-1558)
Earl Chew discovered that fetchmail can be made to de-reference a NULL
pointer when contacting SMTP servers. This vulnerability can be used
by attackers who control the SMTP server to crash fetchmail and cause
a denial of service. (CVE-2007-4565)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2007-06-06·CVSS 2.6
CVE-2007-1558 [LOW] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Gaëtan Leurent showed a weakness in APOP authentication. An attacker
posing as a trusted server could recover portions of the user's
password via multiple authentication attempts. (CVE-2007-1558)
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious email, an attacker could execute
arbitrary code with the user's privileges. Please note that JavaScript
is disabled by default for emails, and it is not recommended to enable
it. (CVE-2007-2867, CVE-2007-2868)
Instructions: After a standard system upgrade you need to restart Thunderbird to effect
the necessary changes.
Red Hat
fetchmail/mutt/evolution/...: APOP password disclosure vulnerability
vendor_redhat·2007-04-02·CVSS 2.6
CVE-2007-1558 [LOW] fetchmail/mutt/evolution/...: APOP password disclosure vulnerability
fetchmail/mutt/evolution/...: APOP password disclosure vulnerability
The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.
Debian
CVE-2007-1558: balsa - The APOP protocol allows remote attackers to guess the first 3 characters of a p...
vendor_debian·2007·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558: balsa - The APOP protocol allows remote attackers to guess the first 3 characters of a p...
The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.
Scope: local
bookworm: resolved (fixed in 2.3.17-1)
bullseye: resolved (fixed in 2.3.17-1)
forky: resolved (fixed in 2.3.17-1)
sid: resolved (fixed in 2.3.17-1)
trixie: resolved (fixed in 2.3.17-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-5297 Multiple mutt tempfile race conditions
bugzilla·2007-07-20·CVSS 1.2
CVE-2006-5297 [LOW] CVE-2006-5297 Multiple mutt tempfile race conditions
CVE-2006-5297 Multiple mutt tempfile race conditions
Clone for RHEL2.1
+++ This bug was initially created as a clone of Bug #211085 +++
Description of problem:
Mutt contains two race condition issues in its temporary file handling system.
First one is caused by O_EXCL problem on NFS volumes (CVE-2006-5297). Second one
is lack of check of file mode and ownership of temporary file after file
creation attempt (CVE-2006-5298).
Version-Release number of selected component (if applicable):
All mutt versions prior to 1.5.12
mutt 1.4.1-12.el4
How reproducible:
Racing with mutt wile it attempts to create and use a temporary file.
Fix:
This [1] is how was the issue fixed in mutt's CVS, following the discussion and
patch proposal in mutt-dev mailing list [2]. Eventually review.
[1] http:/
Bugzilla
CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
bugzilla·2007-06-18·CVSS 4.3
CVE-2007-1362 [MEDIUM] CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
-- Additional comment from [email protected] on 2007-05-30 12:47 EST --
Thunderbird 2.0.0.4 is being released to fix the following security flaws:
CVE-2007-2867 MFSA 2007-12 Layout engine
CVE-2007-2868 MFSA 2007-12 Javascript engine
CVE-2007-2869 MFSA 2007-13
CVE-2007-1362 MFSA 2007-14
CVE-2007-1558 MFSA 2007-15
CVE-2007-2871 MFSA 2007-17
Please see the upstream advisories for detailed flaw information:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Discussion:
thunderbird-2.0.0.4-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
bugzilla·2007-05-31·CVSS 4.3
CVE-2007-1362 [MEDIUM] CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
+++ This bug was initially created as a clone of Bug #241671 +++
Thunderbird 1.5.0.12 is being released to fix the following security flaws:
CVE-2007-2867 MFSA 2007-12 Layout engine
CVE-2007-2868 MFSA 2007-12 Javascript engine
CVE-2007-2869 MFSA 2007-13
CVE-2007-1362 MFSA 2007-14
CVE-2007-1558 MFSA 2007-15
CVE-2007-2871 MFSA 2007-17
Please see the upstream advisories for detailed flaw information:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Discussion:
FC6 reached EOL.
Bugzilla
CVE-2007-1362 Miltiple Seamonkey flaws (CVE-2007-1562, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)
bugzilla·2007-05-31·CVSS 4.3
CVE-2007-1362 [MEDIUM] CVE-2007-1362 Miltiple Seamonkey flaws (CVE-2007-1562, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)
CVE-2007-1362 Miltiple Seamonkey flaws (CVE-2007-1562, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)
+++ This bug was initially created as a clone of Bug #241672 +++
Seamonkey 1.0.9 is being released to fix the following security flaws:
CVE-2007-1562 MFSA 2007-11
CVE-2007-2867 MFSA 2007-12 Layout engine
CVE-2007-2868 MFSA 2007-12 Javascript engine
CVE-2007-2869 MFSA 2007-13
CVE-2007-1362 MFSA 2007-14
CVE-2007-1558 MFSA 2007-15
CVE-2007-2870 MFSA 2007-16
CVE-2007-2871 MFSA 2007-17
Please see the upstream advisories for detailed flaw information:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Discussion:
Fedora Core 5 is no longer supported, could you please reproduce this with the
updated version of the currently support
Bugzilla
CVE-2007-1362 Miltiple Seamonkey flaws (CVE-2007-1562, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)
bugzilla·2007-05-29·CVSS 4.3
CVE-2007-1362 [MEDIUM] CVE-2007-1362 Miltiple Seamonkey flaws (CVE-2007-1562, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)
CVE-2007-1362 Miltiple Seamonkey flaws (CVE-2007-1562, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871)
Seamonkey 1.0.9 is being released to fix the following security flaws:
CVE-2007-1562 MFSA 2007-11
CVE-2007-2867 MFSA 2007-12 Layout engine
CVE-2007-2868 MFSA 2007-12 Javascript engine
CVE-2007-2869 MFSA 2007-13
CVE-2007-1362 MFSA 2007-14
CVE-2007-1558 MFSA 2007-15
CVE-2007-2870 MFSA 2007-16
CVE-2007-2871 MFSA 2007-17
Please see the upstream advisories for detailed flaw information:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Discussion:
These flaws also affect Seamonkey as shipped in RHEL 2.1 and 3
---
Lifting embargo
---
An advisory has been issued which should help the problem
described in this bug report. This r
Bugzilla
CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
bugzilla·2007-05-29·CVSS 4.3
CVE-2007-1362 [MEDIUM] CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
CVE-2007-1362 Miltiple Thunderbird flaws (CVE-2007-1558, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2871)
Seamonkey 1.0.9 is being released to fix the following security flaws:
CVE-2007-2867 MFSA 2007-12 Layout engine
CVE-2007-2868 MFSA 2007-12 Javascript engine
CVE-2007-2869 MFSA 2007-13
CVE-2007-1362 MFSA 2007-14
CVE-2007-1558 MFSA 2007-15
CVE-2007-2871 MFSA 2007-17
Please see the upstream advisories for detailed flaw information:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Discussion:
Lifting embargo
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow
Bugzilla
CVE-2007-1558 fetchmail/mutt/evolution/...: APOP password disclosure vulnerability
bugzilla·2007-05-24·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558 fetchmail/mutt/evolution/...: APOP password disclosure vulnerability
CVE-2007-1558 fetchmail/mutt/evolution/...: APOP password disclosure vulnerability
"A flaw was found in the way fetchmail processed certain APOP authentication
requests. By sending certain responses when fetchmail attempted to authenticate
against an APOP server, a remote attacker could potentially acquire certain
portions of a user's authentication credentials. (CVE-2007-1558)
http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt
https://developer.berlios.de/project/shownotes.php?group_id=1824&release_id=12610
http://www.securityfocus.com/archive/1/464477/30/0/threaded
Discussion:
Also mutt, See
http://dev.mutt.org/trac/ticket/2846
---
Created attachment 347172
Local copy of Gaëtan Leurent's paper
Downloaded from:
http://www.eleves.ens.fr/home/leurent/files/APOP_FSE07.pdf
---
This
Bugzilla
CVE-2007-1558 Evolution APOP information disclosure
bugzilla·2007-05-01·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558 Evolution APOP information disclosure
CVE-2007-1558 Evolution APOP information disclosure
Bugzilla
CVE-2007-1558 Evolution APOP information disclosure
bugzilla·2007-05-01·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558 Evolution APOP information disclosure
CVE-2007-1558 Evolution APOP information disclosure
+++ This bug was initially created as a clone of Bug #235289 +++
A flaw has been found in the way Evolution handles APOP authentication. It is
possible for an attacker to discover authentication credentials by sending
certain responses to Evolution.
The upstream bug has more details:
http://bugzilla.gnome.org/show_bug.cgi?id=424373
Discussion:
I'm moving to version to RHEL4. This flaw affects RHEL 3 and 4.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for
Bugzilla
CVE-2007-1558: claws-mail APOP vulnerability
bugzilla·2007-04-20·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558: claws-mail APOP vulnerability
CVE-2007-1558: claws-mail APOP vulnerability
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1558
"The APOP protocol allows remote attackers to guess the first 3 characters of a
password via man-in-the-middle (MITM) attacks that use crafted message IDs and
MD5 collisions. NOTE: this design-level issue potentially affects all products
that use APOP, including (1) Thunderbird, (2) Evolution, (3) mutt, and (4)
fetchmail."
According to upstream, fixed in 2.9.1.
http://www.claws-mail.org/news.php
Discussion:
Thanks for reporting. Fixed and pushed.
Bugzilla
CVE-2007-1558 Evolution APOP information disclosure
bugzilla·2007-04-04·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558 Evolution APOP information disclosure
CVE-2007-1558 Evolution APOP information disclosure
+++ This bug was initially created as a clone of Bug #235289 +++
A flaw has been found in the way Evolution handles APOP authentication. It is
possible for an attacker to discover authentication credentials by sending
certain responses to Evolution.
The upstream bug has more details:
http://bugzilla.gnome.org/show_bug.cgi?id=424373
This flaw should also affect FC5
Discussion:
Fixed in evolution-data-server-1.8.3-5.fc6.
Also ported to 1.6.3-3.fc5 and 1.10.1-2.fc7.
Bugzilla
CVE-2007-1558 Evolution APOP information disclosure
bugzilla·2007-04-04·CVSS 2.6
CVE-2007-1558 [LOW] CVE-2007-1558 Evolution APOP information disclosure
CVE-2007-1558 Evolution APOP information disclosure
A flaw has been found in the way Evolution handles APOP authentication. It is
possible for an attacker to discover authentication credentials by sending
certain responses to Evolution.
The upstream bug has more details:
http://bugzilla.gnome.org/show_bug.cgi?id=424373
This flaw should also affect RHEL 3 and 4.
Discussion:
*** Bug 238564 has been marked as a duplicate of this bug. ***
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://balsa.gnome.org/download.htmlhttp://docs.info.apple.com/article.html?artnum=305530http://fetchmail.berlios.de/fetchmail-SA-2007-01.txthttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://mail.gnome.org/archives/balsa-list/2007-July/msg00000.htmlhttp://secunia.com/advisories/25353http://secunia.com/advisories/25402http://secunia.com/advisories/25476http://secunia.com/advisories/25496http://secunia.com/advisories/25529http://secunia.com/advisories/25534http://secunia.com/advisories/25546http://secunia.com/advisories/25559http://secunia.com/advisories/25664http://secunia.com/advisories/25750http://secunia.com/advisories/25798http://secunia.com/advisories/25858http://secunia.com/advisories/25894http://secunia.com/advisories/26083http://secunia.com/advisories/26415http://secunia.com/advisories/35699http://security.gentoo.org/glsa/glsa-200706-06.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.571857http://sourceforge.net/forum/forum.php?forum_id=683706http://sylpheed.sraoss.jp/en/news.htmlhttp://www.claws-mail.org/news.phphttp://www.debian.org/security/2007/dsa-1300http://www.debian.org/security/2007/dsa-1305http://www.mandriva.com/security/advisories?name=MDKSA-2007:105http://www.mandriva.com/security/advisories?name=MDKSA-2007:107http://www.mandriva.com/security/advisories?name=MDKSA-2007:113http://www.mandriva.com/security/advisories?name=MDKSA-2007:119http://www.mandriva.com/security/advisories?name=MDKSA-2007:131http://www.mozilla.org/security/announce/2007/mfsa2007-15.htmlhttp://www.novell.com/linux/security/advisories/2007_14_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_36_mozilla.htmlhttp://www.openwall.com/lists/oss-security/2009/08/15/1http://www.openwall.com/lists/oss-security/2009/08/18/1http://www.redhat.com/support/errata/RHSA-2007-0344.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0353.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0385.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0386.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0401.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0402.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1140.htmlhttp://www.securityfocus.com/archive/1/464477/30/0/threadedhttp://www.securityfocus.com/archive/1/464569/100/0/threadedhttp://www.securityfocus.com/archive/1/470172/100/200/threadedhttp://www.securityfocus.com/archive/1/471455/100/0/threadedhttp://www.securityfocus.com/archive/1/471720/100/0/threadedhttp://www.securityfocus.com/archive/1/471842/100/0/threadedhttp://www.securityfocus.com/bid/23257http://www.securitytracker.com/id?1018008http://www.trustix.org/errata/2007/0019/http://www.trustix.org/errata/2007/0024/http://www.ubuntu.com/usn/usn-469-1http://www.ubuntu.com/usn/usn-520-1http://www.us-cert.gov/cas/techalerts/TA07-151A.htmlhttp://www.vupen.com/english/advisories/2007/1466http://www.vupen.com/english/advisories/2007/1467http://www.vupen.com/english/advisories/2007/1468http://www.vupen.com/english/advisories/2007/1480http://www.vupen.com/english/advisories/2007/1939http://www.vupen.com/english/advisories/2007/1994http://www.vupen.com/english/advisories/2007/2788http://www.vupen.com/english/advisories/2008/0082https://issues.rpath.com/browse/RPL-1231https://issues.rpath.com/browse/RPL-1232https://issues.rpath.com/browse/RPL-1424https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9782ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://balsa.gnome.org/download.htmlhttp://docs.info.apple.com/article.html?artnum=305530http://fetchmail.berlios.de/fetchmail-SA-2007-01.txthttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579http://lists.apple.com/archives/security-announce/2007/May/msg00004.htmlhttp://mail.gnome.org/archives/balsa-list/2007-July/msg00000.htmlhttp://secunia.com/advisories/25353http://secunia.com/advisories/25402http://secunia.com/advisories/25476http://secunia.com/advisories/25496http://secunia.com/advisories/25529http://secunia.com/advisories/25534http://secunia.com/advisories/25546http://secunia.com/advisories/25559http://secunia.com/advisories/25664http://secunia.com/advisories/25750http://secunia.com/advisories/25798http://secunia.com/advisories/25858http://secunia.com/advisories/25894http://secunia.com/advisories/26083http://secunia.com/advisories/26415http://secunia.com/advisories/35699http://security.gentoo.org/glsa/glsa-200706-06.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.571857http://sourceforge.net/forum/forum.php?forum_id=683706
+ 46 more references
2007-04-16
Published