USN-294-1: courier vulnerability
9 June 2006
courier vulnerability
Releases
Details
A Denial of Service vulnerability has been found in the function for
encoding email addresses. Addresses containing a '=' before the '@'
character caused the Courier to hang in an endless loop, rendering the
service unusable.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 6.06
-
courier-mta
-
0.47-13ubuntu5.1
Ubuntu 5.10
-
courier-mta
-
0.47-3ubuntu7.2
Ubuntu 5.04
-
courier-mta
-
0.47-3ubuntu1.5
In general, a standard system upgrade is sufficient to effect the
necessary changes.