Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian Stretch DLA-2866-1: uw-imap Security Update for IMAP Access

debian lts
Calendar Grey December 29, 2021
Dist Debian Esm H88
Enhance uw-imap software versions in Debian LTS DLA-2866-1 to restrict mailbox access via rsh/ssh protocols as a standard setting.
Access to IMAP mailboxes through running imapd over rsh and ssh is now disabled by default in uw-imap, the University of Washington IMAP Toolkit

Summary

For Debian 9 stretch, this problem has been fixed in version
8:2007f~dfsg-5+deb9u1.

We recommend that you upgrade your uw-imap packages.

For the detailed security status of uw-imap please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/uw-imap

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: uw-imap
Version: 8:2007f~dfsg-5+deb9u1
CVE ID: CVE-2018-19518
Debian Bug: 914632

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here