Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.2: SUSE-SU-2021:0646-1 Moderate Email Issue Fix

opensuse
Calendar Grey May 1, 2021
Dist Opensuse Esm H88
A security update addressing one vulnerability in openSUSE's postsrsd has been issued. For further information, please consult the announcement ID.
An update that fixes one vulnerability is now available

Description

This update for postsrsd fixes the following issues:

Update to release 1.11 [boo#1180251]

* Drop group privileges as well as user privileges

* Fixed: The subprocess that talks to Postfix could be caused to hang with

a very long email address. [CVE-2020-35573]

Update to release 1.6

* Fix endianness issue with SHA-1 implementation

* Add dual stack support

* Make SRS separator configurable

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-646=1

Package List

- openSUSE Leap 15.2 (x86_64):

postsrsd-1.11-lp152.4.3.1

postsrsd-debuginfo-1.11-lp152.4.3.1

postsrsd-debugsource-1.11-lp152.4.3.1

References

https://www.suse.com/security/cve/CVE-2020-35573.html

https://bugzilla.suse.com/1180251

Announcement ID: openSUSE-SU-2021:0646-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here