==========================================================================
Ubuntu Security Notice USN-6790-1
May 28, 2024

amavisd-new vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

amavisd-new could be made to bypass security measures.

Software Description:
- amavisd-new: Interface between MTA and virus scanner/content filters

Details:

It was discovered that amavisd-new incorrectly handled certain MIME email
messages with multiple boundary parameters. A remote attacker could
possibly use this issue to bypass checks for banned files or malware.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
   amavisd-new                     1:2.13.0-3ubuntu2

Ubuntu 23.10
   amavisd-new                     1:2.13.0-3ubuntu1.1

Ubuntu 22.04 LTS
   amavisd-new                     1:2.12.2-1ubuntu1.1

Ubuntu 20.04 LTS
   amavisd-new                     1:2.11.0-6.1ubuntu1.1

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6790-1
   CVE-2024-28054

Package Information:
   https://launchpad.net/ubuntu/+source/amavisd-new/1:2.13.0-3ubuntu2
   https://launchpad.net/ubuntu/+source/amavisd-new/1:2.13.0-3ubuntu1.1
   https://launchpad.net/ubuntu/+source/amavisd-new/1:2.12.2-1ubuntu1.1
   https://launchpad.net/ubuntu/+source/amavisd-new/1:2.11.0-6.1ubuntu1.1

Ubuntu 6790-1: amavisd-new Security Advisory Updates

May 28, 2024
amavisd-new could be made to bypass security measures.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: amavisd-new could be made to bypass security measures. Software Description: - amavisd-new: Interface between MTA and virus scanner/content filters Details: It was discovered that amavisd-new incorrectly handled certain MIME email messages with multiple boundary parameters. A remote attacker could possibly use this issue to bypass checks for banned files or malware.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS amavisd-new 1:2.13.0-3ubuntu2 Ubuntu 23.10 amavisd-new 1:2.13.0-3ubuntu1.1 Ubuntu 22.04 LTS amavisd-new 1:2.12.2-1ubuntu1.1 Ubuntu 20.04 LTS amavisd-new 1:2.11.0-6.1ubuntu1.1 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6790-1

CVE-2024-28054

Severity
Ubuntu Security Notice USN-6790-1

Package Information

https://launchpad.net/ubuntu/+source/amavisd-new/1:2.13.0-3ubuntu2 https://launchpad.net/ubuntu/+source/amavisd-new/1:2.13.0-3ubuntu1.1 https://launchpad.net/ubuntu/+source/amavisd-new/1:2.12.2-1ubuntu1.1 https://launchpad.net/ubuntu/+source/amavisd-new/1:2.11.0-6.1ubuntu1.1

Related News