emacs movemail POP utility (SSA:2005-201-02)
Posted on: 07/21/2005 04:35 AM
New emacs packages are available for Slackware 10.1 and -current to a security issue with the movemail utility for retrieving mail from a POP mail server. If used to connect to a malicious POP server, it is possible for the server to cause the execution of arbitrary code as the user running emacs.
Here are the details from the Slackware 10.1 ChangeLog: +--------------------------+ patches/packages/emacs-21.4a-i486-1.tgz: Upgraded to emacs-21.4a. This fixes a vulnerability in the movemail utility when connecting to a malicious POP server that may allow the execution of arbitrary code as the user running emacs. (* Security fix *) +--------------------------+
Where to find the new packages: +-----------------------------+