It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language. . Package : libphp-phpmailer Version : 5.2.9+dfsg-2+deb8u6 CVE ID : CVE-2020-13625 It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language. The `Content-Type` and `Content-Disposition` headers could have permitted file attachments that bypassed attachment filters which match on filename extensions. For more information, please see the following URL: https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-f7hx-fqxw-rvvj For Debian 8 "Jessie", this issue has been fixed in libphp-phpmailer version 5.2.9+dfsg-2+deb8u6. We recommend that you upgrade your libphp-phpmailer packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - -- ,'`. : :' : Chris Lamb `. `'`
If fetchmail is running in daemon mode, it must be restarted for this update to take effect (use the "fetchmail --quit" command to stop the fetchmail process).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-8770 2009-08-20 20:32:57 --------------------------------------------------------------------------------Name : fetchmail Product : Fedora 10 Version : 6.3.8 Release : 9.fc10 URL : https://www.berlios.de/software/fetchmail/ Summary : A remote mail retrieval and forwarding utility Description : Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections. --------------------------------------------------------------------------------Update Information: If fetchmail is running in daemon mode, it must be restarted for this update to take effect (use the "fetchmail --quit" command to stop the fetchmail process). --------------------------------------------------------------------------------ChangeLog: * Wed Aug 19 2009 Vitezslav Crhonek - 6.3.8-9 - Fix SSL null terminator bypass (CVE-2009-2666) --------------------------------------------------------------------------------References: [ 1 ] Bug #515804 - CVE-2009-2666 fetchmail: SSL null terminator bypass https://bugzilla.redhat.com/show_bug.cgi?id=515804 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update fetchmail' at the command line. For more information, refer to "Managing Softwarewith yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.