An update that solves two vulnerabilities, contains three features and has four fixes is now available. . openSUSE Security Update: Security update for fetchmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1591-1 Rating: moderate References: #1152964 #1174075 #1181400 #1188875 #1190069 #1190896 SLE-17903 SLE-18059 SLE-18159 Cross-References: CVE-2021-36386 CVE-2021-39272 CVSS scores: CVE-2021-36386 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-36386 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-39272 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves two vulnerabilities, contains three features and has four fixes is now available. Description: This update for fetchmail fixes the following issues: - CVE-2021-36386: Fixed DoS or information disclosure in some configurations (bsc#1188875). - CVE-2021-39272: Fixed STARTTLS session encryption bypassing (fetchmail-SA-2021-02) (bsc#1190069). - Update to 6.4.22 (bsc#1152964, jsc#SLE-18159, jsc#SLE-17903, jsc#SLE-18059) - Remove all python2 dependencies (bsc#1190896). - De-hardcode /usr/lib path for launch executable (bsc#1174075). - Added hardening to systemd service(s) (bsc#1181400). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1591=1 Package List: - openSUSE Leap 15.2 (x86_64): fetchmail-6.4.22-lp152.6.12.1 fetchmail-debuginfo-6.4.22-lp152.6.12.1 fetchmail-debugsource-6.4.22-lp152.6.12.1 fetchmailconf-6.4.22-lp152.6.12.1 References: https://www.suse.com/security/cve/CVE-2021-36386.html https://www.suse.com/security/cve/CVE-2021-39272.html https://bugzilla.suse.com/1152964 https://bugzilla.suse.com/1174075 https://bugzilla.suse.com/1181400 https://bugzilla.suse.com/1188875 https://bugzilla.suse.com/1190069 https://bugzilla.suse.com/1190896 . Updates for fetchmail on openSUSE address two vulnerabilities along with several enhancements.. fetchmail update, openSUSE security, patch installation. . LinuxSecurity.com Team
An update that solves two vulnerabilities, contains three features and has four fixes is now available. . openSUSE Security Update: Security update for fetchmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:4018-1 Rating: moderate References: #1152964 #1174075 #1181400 #1188875 #1190069 #1190896 SLE-17903 SLE-18059 SLE-18159 Cross-References: CVE-2021-36386 CVE-2021-39272 CVSS scores: CVE-2021-36386 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-36386 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-39272 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves two vulnerabilities, contains three features and has four fixes is now available. Description: This update for fetchmail fixes the following issues: - CVE-2021-36386: Fixed DoS or information disclosure in some configurations (bsc#1188875). - CVE-2021-39272: Fixed STARTTLS session encryption bypassing (fetchmail-SA-2021-02) (bsc#1190069). - Update to 6.4.22 (bsc#1152964, jsc#SLE-18159, jsc#SLE-17903, jsc#SLE-18059) - Remove all python2 dependencies (bsc#1190896). - De-hardcode /usr/lib path for launch executable (bsc#1174075). - Added hardening to systemd service(s) (bsc#1181400). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-4018=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): fetchmail-6.4.22-20.20.1 fetchmail-debuginfo-6.4.22-20.20.1 fetchmail-debugsource-6.4.22-20.20.1 fetchmailconf-6.4.22-20.20.1 References: https://www.suse.com/security/cve/CVE-2021-36386.html https://www.suse.com/security/cve/CVE-2021-39272.html https://bugzilla.suse.com/1152964 https://bugzilla.suse.com/1174075 https://bugzilla.suse.com/1181400 https://bugzilla.suse.com/1188875 https://bugzilla.suse.com/1190069 https://bugzilla.suse.com/1190896 . Patch release for fetchmail on openSUSE tackling two vulnerabilities of moderate concern. Notable enhancements incorporated.. openSUSE Fetchmail Update, Moderate Security Patch, Open Source Software Fix. . LinuxSecurity.com Team
Update to fetchmail 6.4.24 fixes STARTTLS session encryption bypassing. (CVE-2021-39272) References: - https://bugs.mageia.org/show_bug.cgi?id=29420 . MGASA-2021-0548 - Updated fetchmail packages fix security vulnerability Publication date: 10 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0548.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-39272 Update to fetchmail 6.4.24 fixes STARTTLS session encryption bypassing. (CVE-2021-39272) References: - https://bugs.mageia.org/show_bug.cgi?id=29420 - https://www.fetchmail.info/fetchmail-SA-2021-02.txt - https://lists.fedoraproject.org/archives/list/
Update to fetchmail-6.4.22 (CVE-2021-39272). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-e61a978fef 2021-09-24 20:04:10.619598 --------------------------------------------------------------------------------Name : fetchmail Product : Fedora 35 Version : 6.4.22 Release : 1.fc35 URL : https://www.fetchmail.info/ Summary : A remote mail retrieval and forwarding utility Description : Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections. --------------------------------------------------------------------------------Update Information: Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------ChangeLog: * Thu Sep 16 2021 Vitezslav Crhonek - 6.4.22-1 - Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------References: [ 1 ] Bug #1999190 - CVE-2021-39272 fetchmail: STARTTLS session encryption bypassing https://bugzilla.redhat.com/show_bug.cgi?id=1999190 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-e61a978fef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to fetchmail-6.4.22 (CVE-2021-39272). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-ddefbdbb46 2021-09-24 20:31:06.232150 --------------------------------------------------------------------------------Name : fetchmail Product : Fedora 34 Version : 6.4.22 Release : 1.fc34 URL : https://www.fetchmail.info/ Summary : A remote mail retrieval and forwarding utility Description : Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections. --------------------------------------------------------------------------------Update Information: Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------ChangeLog: * Thu Sep 16 2021 Vitezslav Crhonek - 6.4.22-1 - Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------References: [ 1 ] Bug #1999190 - CVE-2021-39272 fetchmail: STARTTLS session encryption bypassing https://bugzilla.redhat.com/show_bug.cgi?id=1999190 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-ddefbdbb46' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.