Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
202

openSUSE: 2021:1591-1 moderate: fetchmail DoS and Encryption Bypass

An update that solves two vulnerabilities, contains three features and has four fixes is now available. . openSUSE Security Update: Security update for fetchmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1591-1 Rating: moderate References: #1152964 #1174075 #1181400 #1188875 #1190069 #1190896 SLE-17903 SLE-18059 SLE-18159 Cross-References: CVE-2021-36386 CVE-2021-39272 CVSS scores: CVE-2021-36386 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-36386 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-39272 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves two vulnerabilities, contains three features and has four fixes is now available. Description: This update for fetchmail fixes the following issues: - CVE-2021-36386: Fixed DoS or information disclosure in some configurations (bsc#1188875). - CVE-2021-39272: Fixed STARTTLS session encryption bypassing (fetchmail-SA-2021-02) (bsc#1190069). - Update to 6.4.22 (bsc#1152964, jsc#SLE-18159, jsc#SLE-17903, jsc#SLE-18059) - Remove all python2 dependencies (bsc#1190896). - De-hardcode /usr/lib path for launch executable (bsc#1174075). - Added hardening to systemd service(s) (bsc#1181400). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1591=1 Package List: - openSUSE Leap 15.2 (x86_64): fetchmail-6.4.22-lp152.6.12.1 fetchmail-debuginfo-6.4.22-lp152.6.12.1 fetchmail-debugsource-6.4.22-lp152.6.12.1 fetchmailconf-6.4.22-lp152.6.12.1 References: https://www.suse.com/security/cve/CVE-2021-36386.html https://www.suse.com/security/cve/CVE-2021-39272.html https://bugzilla.suse.com/1152964 https://bugzilla.suse.com/1174075 https://bugzilla.suse.com/1181400 https://bugzilla.suse.com/1188875 https://bugzilla.suse.com/1190069 https://bugzilla.suse.com/1190896 . Updates for fetchmail on openSUSE address two vulnerabilities along with several enhancements.. fetchmail update, openSUSE security, patch installation. . LinuxSecurity.com Team

Calendar%202 Dec 17, 2021 OpenSUSE
202

openSUSE Leap 15.3 Security Update: 2021:4018-1 Moderate fetchmail DoS

An update that solves two vulnerabilities, contains three features and has four fixes is now available. . openSUSE Security Update: Security update for fetchmail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:4018-1 Rating: moderate References: #1152964 #1174075 #1181400 #1188875 #1190069 #1190896 SLE-17903 SLE-18059 SLE-18159 Cross-References: CVE-2021-36386 CVE-2021-39272 CVSS scores: CVE-2021-36386 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-36386 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-39272 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves two vulnerabilities, contains three features and has four fixes is now available. Description: This update for fetchmail fixes the following issues: - CVE-2021-36386: Fixed DoS or information disclosure in some configurations (bsc#1188875). - CVE-2021-39272: Fixed STARTTLS session encryption bypassing (fetchmail-SA-2021-02) (bsc#1190069). - Update to 6.4.22 (bsc#1152964, jsc#SLE-18159, jsc#SLE-17903, jsc#SLE-18059) - Remove all python2 dependencies (bsc#1190896). - De-hardcode /usr/lib path for launch executable (bsc#1174075). - Added hardening to systemd service(s) (bsc#1181400). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-4018=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): fetchmail-6.4.22-20.20.1 fetchmail-debuginfo-6.4.22-20.20.1 fetchmail-debugsource-6.4.22-20.20.1 fetchmailconf-6.4.22-20.20.1 References: https://www.suse.com/security/cve/CVE-2021-36386.html https://www.suse.com/security/cve/CVE-2021-39272.html https://bugzilla.suse.com/1152964 https://bugzilla.suse.com/1174075 https://bugzilla.suse.com/1181400 https://bugzilla.suse.com/1188875 https://bugzilla.suse.com/1190069 https://bugzilla.suse.com/1190896 . Patch release for fetchmail on openSUSE tackling two vulnerabilities of moderate concern. Notable enhancements incorporated.. openSUSE Fetchmail Update, Moderate Security Patch, Open Source Software Fix. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2021 OpenSUSE
203

Mageia 8: 2021-0548 Critical Update Fetchmail STARTTLS Bypass

Update to fetchmail 6.4.24 fixes STARTTLS session encryption bypassing. (CVE-2021-39272) References: - https://bugs.mageia.org/show_bug.cgi?id=29420 . MGASA-2021-0548 - Updated fetchmail packages fix security vulnerability Publication date: 10 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0548.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-39272 Update to fetchmail 6.4.24 fixes STARTTLS session encryption bypassing. (CVE-2021-39272) References: - https://bugs.mageia.org/show_bug.cgi?id=29420 - https://www.fetchmail.info/fetchmail-SA-2021-02.txt - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/L3XJ6XLEJCEZCAM5LGGD6XBCC522QLG4/ - https://www.cve.org/CVERecord?id=CVE-2021-39272 SRPMS: - 8/core/fetchmail-6.4.24-1.mga8 . Fetchmail version 6.4.24 addresses a critical STARTTLS encryption bypass issue in Mageia; click for further information.. Mageia Security, Fetchmail Update, Encryption Bypass, Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 10, 2021 Critical Mageia
89

Fedora 35: 2021-e61a978fef Moderate: Fetchmail STARTTLS Bypass

Update to fetchmail-6.4.22 (CVE-2021-39272). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-e61a978fef 2021-09-24 20:04:10.619598 --------------------------------------------------------------------------------Name : fetchmail Product : Fedora 35 Version : 6.4.22 Release : 1.fc35 URL : https://www.fetchmail.info/ Summary : A remote mail retrieval and forwarding utility Description : Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections. --------------------------------------------------------------------------------Update Information: Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------ChangeLog: * Thu Sep 16 2021 Vitezslav Crhonek - 6.4.22-1 - Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------References: [ 1 ] Bug #1999190 - CVE-2021-39272 fetchmail: STARTTLS session encryption bypassing https://bugzilla.redhat.com/show_bug.cgi?id=1999190 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-e61a978fef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The recent release of fetchmail version 6.4.22 resolves a critical STARTTLS encryption vulnerability affecting Fedora 35 installations.. Fedora Fetchmail Update, Email Retrieval Tool, STARTTLS Bypass Fix. . LinuxSecurity.com Team

Calendar%202 Sep 24, 2021 Fedora
89

Fedora 34 Fetchmail Moderate: 2021-ddefbdbb46 Encryption Bypass Fix

Update to fetchmail-6.4.22 (CVE-2021-39272). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-ddefbdbb46 2021-09-24 20:31:06.232150 --------------------------------------------------------------------------------Name : fetchmail Product : Fedora 34 Version : 6.4.22 Release : 1.fc34 URL : https://www.fetchmail.info/ Summary : A remote mail retrieval and forwarding utility Description : Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections. --------------------------------------------------------------------------------Update Information: Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------ChangeLog: * Thu Sep 16 2021 Vitezslav Crhonek - 6.4.22-1 - Update to fetchmail-6.4.22 (CVE-2021-39272) --------------------------------------------------------------------------------References: [ 1 ] Bug #1999190 - CVE-2021-39272 fetchmail: STARTTLS session encryption bypassing https://bugzilla.redhat.com/show_bug.cgi?id=1999190 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-ddefbdbb46' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade to fetchmail-6.4.22 to resolve STARTTLS encryption vulnerability in Fedora 34. Act promptly to boost your security.. Fedora Updates, Fetchmail Security, Mail Retrieval Utility. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 24, 2021 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here