Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9 DLA-3052-1 Critical: Cyrus IMAP Denial Of Service

It was discovered that the Cyrus IMAP server was prone to a denial of service attack via input that is mishandled during hash-table interaction. Furthermore it allowed privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over . -------------------------------------------------------------------------Debian LTS Advisory DLA-3052-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 20, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : cyrus-imapd Version : 2.5.10-3+deb9u3 CVE ID : CVE-2019-18928 CVE-2021-33582 Debian Bug : 993433 It was discovered that the Cyrus IMAP server was prone to a denial of service attack via input that is mishandled during hash-table interaction. Furthermore it allowed privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection. For Debian 9 stretch, these problems have been fixed in version 2.5.10-3+deb9u3. We recommend that you upgrade your cyrus-imapd packages. For the detailed security status of cyrus-imapd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cyrus-imapd Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The recent Cyrus IMAP security patch mitigates denial of service vulnerabilities and privilege elevation concerns in Debian LTS.. Cyrus IMAP Update, Debian Security, Denial of Service Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 19, 2022 Critical Debian LTS
91

Gentoo: GLSA-202006-24 Normal: Postfix Security Issue Causes DoS Attack

An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202006-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Cyrus IMAP Server: Access restriction bypass Date: June 15, 2020 Bugs: #703630 ID: 202006-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges. Background ========= The Cyrus IMAP Server is an efficient, highly-scalable IMAP e-mail server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-mail/cyrus-imapd < 3.0.13 > = 3.0.13 Description ========== An issue was discovered in Cyrus IMAP Server where sieve script uploading is excessively trusted. Impact ===== A user can use a sieve script to create any mailbox with administrator privileges. Workaround ========= Disable sieve script uploading until the upgrade is complete. Resolution ========= All Cyrus IMAP Server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-mail/cyrus-imapd-3.0.13" References ========= [ 1 ] CVE-2019-19783 https://nvd.nist.gov/vuln/detail/CVE-2019-19783 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202006-23 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and securityof our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Cyrus IMAP Server vulnerability enables mailbox creation under administrator rights; upgrade suggested. Check Gentoo's advisory for details.. Cyrus IMAP Server, Gentoo Linux, Access Bypass, Security Advisory. . LinuxSecurity.com Team

Calendar 2 Jun 15, 2020 Gentoo
217

Oracle Linux 5 ELSA-2011-1508 Moderate: Cyrus Email Threat Resolutions

The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2011-1508 https://access.redhat.com/errata/RHSA-2011:1508.html The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: cyrus-imapd-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.i386.rpm x86_64: cyrus-imapd-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.x86_64.rpm ia64: cyrus-imapd-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.ia64.rpm SRPMS: https://oss.oracle.com:443/ol5/SRPMS-updates/cyrus-imapd-2.3.7-12.0.1.el5_7.2.src.rpm Description of changes: [2.3.7-12.0.1.el5_7.2] - Enabled lm_sensors-devel build dependency for x86 and x86_64 only [2.3.7-12.2] - fix CVE-2011-3481: NULL pointer dereference via crafted References header in email (#738391) - fix CVE-2011-3372: nntpd authentication bypass (#740822) . Oracle Linux 5 has been issued a significant security patch for cyrus, addressing severe vulnerabilities along with key rpm updates.. Oracle Linux,Cyrus IMAP,Security Update,ELSA-2011-1508,Threat Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 02, 2011 Important Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here