Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-2805-1 Severe: Sup Mail Command Injection Risk

debian
Calendar Grey November 27, 2013
Debian Logo
Ubuntu Security Notice USN-4532-1: Vulnerability in OpenSSH could lead to unauthorized access; users must upgrade promptly to ensure safety.
joernchen of Phenoelit discovered two command injection flaws in Sup, a console-based email client

Summary

CVE-2013-4478

Sup wrongly handled the filename of attachments.

CVE-2013-4479

Sup did not sanitize the content-type of attachments.

For the oldstable distribution (squeeze), these problems have been fixed in
version 0.11-2+nmu1+deb6u1.

For the stable distribution (wheezy), these problems have been fixed in
version 0.12.1+git20120407.aaa852f-1+deb7u1.

We recommend that you upgrade your sup-mail packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: sup-mail
CVE ID: CVE-2013-4478 CVE-2013-4479

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here