|
The SuSE security team discovered during an audit a bug in Mail::Mailer, a Perl module used for sending email, whereby potentially untrusted input is passed to a program such as mailx, which may interpret certain escape sequences as commands to be executed.
This bug has been fixed by removing support for programs such as mailx as a transport for sending mail. Instead, alternative mechanisms are used.
For the stable distribution (woody) this problem has been fixed in version 1.44-1woody1.
For the unstable distribution (sid) this problem will be fixed soon.
We recommend that you update your libmailtools-perl package.
MD5 checksums of the listed files are available in the original advisory.