Attachments with specially crafted filenames could bypass filename-based mail attachment filters.. =========================================================================Ubuntu Security Notice USN-4505-1 September 16, 2020 libphp-phpmailer vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Attachments with specially crafted filenames could bypass filename-based mail attachment filters. Software Description: - libphp-phpmailer: full featured email transfer class for PHP Details: Elar Lang discovered that PHPMailer did not properly escape double quote characters in filenames. A remote attacker could possibly exploit this with a crafted filename to bypass attachment filters that are based on matching filename extensions. (CVE-2020-13625) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libphp-phpmailer 5.2.14+dfsg-2.3+deb9u2build0.18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4505-1 CVE-2020-13625 Package Information: https://launchpad.net/ubuntu/+source/libphp-phpmailer/5.2.14+dfsg-2.3+deb9u2build0.18.04.1 . A critical PHPMailer vulnerability affects Ubuntu 18.04 LTS, allowing remote attackers potential unauthorized actions. Update to mitigate risks promptly. PHPMailer Exploit, Ubuntu Security Notice, Email Attachment Risk. . LinuxSecurity.com Team
Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-6e77507660 2019-07-06 05:07:52.250928 --------------------------------------------------------------------------------Name : libfilezilla Product : Fedora 29 Version : 0.17.1 Release : 1.fc29 URL : https://lib.filezilla-project.org/ Summary : C++ Library for FileZilla Description : libfilezilla is a small and modern C++ library, offering some basic functionality to build high-performing, platform-independent programs. --------------------------------------------------------------------------------Update Information: Bugfixes, and a security fix: Fixed vulnerabilities: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands. --------------------------------------------------------------------------------ChangeLog: * Thu Jun 27 2019 Gwyn Ciesla - 0.17.1-1 - 0.17.1 * Tue Apr 30 2019 Gwyn Ciesla - 0.16.0-1 - 0.16.0 * Fri Feb 1 2019 Fedora Release Engineering - 0.15.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Nov 26 2018 Gwyn Ciesla - 0.15.1-1 - 0.15.1 * Fri Oct 19 2018 Gwyn Ciesla - 0.15.0-1 - 0.15.0 * Fri Oct 5 2018 Gwyn Ciesla - 0.14.0-1 - 0.14.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1724743 - filezilla-3.43.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1724743 --------------------------------------------------------------------------------This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2019-6e77507660' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.