LibEtPan could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7740-1 September 08, 2025 libetpan vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: LibEtPan could be made to crash if it received specially crafted network traffic. Software Description: - libetpan: Mail Framework for C Language Details: It was discovered that LibEtPan incorrectly handled memory when parsing IMAP STATUS responses. A remote attacker could possibly use this issue to cause LibEtPan to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libetpan20 1.9.4-3+deb11u1build0.22.04.1 Ubuntu 20.04 LTS libetpan20 1.9.4-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libetpan20 1.8.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libetpan17 1.6-1ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7740-1 CVE-2022-4121 Package Information: . The Ubuntu Security Notice USN-7740-1 highlights a significant vulnerability in libetpan that may lead to crashing when processing specially designed network traffic.. libetpan crash, Ubuntu 22.04, network vulnerability, deny service, libetpan security. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4256-1
It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3261-1
Null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c. (CVE-2022-4121) References: - https://bugs.mageia.org/show_bug.cgi?id=31214 . MGASA-2022-0470 - Updated libetpan packages fix security vulnerability Publication date: 17 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0470.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-4121 Null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c. (CVE-2022-4121) References: - https://bugs.mageia.org/show_bug.cgi?id=31214 - https://lists.fedoraproject.org/archives/list/
A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-df2f4923ea 2022-12-02 06:21:15.000496 --------------------------------------------------------------------------------Name : libetpan Product : Fedora 35 Version : 1.9.4 Release : 9.fc35 URL : Summary : Portable, efficient middle-ware for different kinds of mail access Description : The purpose of this mail library is to provide a portable, efficient middle-ware for different kinds of mail access. When using the drivers interface, the interface is the same for all kinds of mail access, remote and local mailboxes. --------------------------------------------------------------------------------Update Information: A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 23 2022 Mamoru TASAKA - 1.9.4-9 - Workaround for CVE-2022-4121 (bug 2144914) * Thu Jul 21 2022 Fedora Release Engineering - 1.9.4-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Thu Jan 20 2022 Fedora Release Engineering - 1.9.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2144915 - libetpan: Null pointer dereference in mailimap_mailbox_data_status_free inlow-level/imap/mailimap_types.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2144915 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-df2f4923ea' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-de3e565494 2022-12-02 01:36:47.412982 --------------------------------------------------------------------------------Name : libetpan Product : Fedora 36 Version : 1.9.4 Release : 9.fc36 URL : Summary : Portable, efficient middle-ware for different kinds of mail access Description : The purpose of this mail library is to provide a portable, efficient middle-ware for different kinds of mail access. When using the drivers interface, the interface is the same for all kinds of mail access, remote and local mailboxes. --------------------------------------------------------------------------------Update Information: A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 23 2022 Mamoru TASAKA - 1.9.4-9 - Workaround for CVE-2022-4121 (bug 2144914) * Thu Jul 21 2022 Fedora Release Engineering - 1.9.4-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2144915 - libetpan: Null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2144915 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-de3e565494' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f092bc8f7b 2022-12-02 01:19:01.664504 --------------------------------------------------------------------------------Name : libetpan Product : Fedora 37 Version : 1.9.4 Release : 9.fc37 URL : Summary : Portable, efficient middle-ware for different kinds of mail access Description : The purpose of this mail library is to provide a portable, efficient middle-ware for different kinds of mail access. When using the drivers interface, the interface is the same for all kinds of mail access, remote and local mailboxes. --------------------------------------------------------------------------------Update Information: A potential bug is found on libetpan that when IMAP client receives invalid STATUS response, an invalid free can occur on mailimap_mailbox_data_status_free(). This bug is now assigned as CVE-2022-4121. Although the formal fix is under discussion, this update rpm adds a quick fix for this issue. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 23 2022 Mamoru TASAKA - 1.9.4-9 - Workaround for CVE-2022-4121 (bug 2144914) --------------------------------------------------------------------------------References: [ 1 ] Bug #2144915 - libetpan: Null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2144915 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2022-f092bc8f7b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
LibEtPan could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-4598-1 October 22, 2020 libetpan vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: LibEtPan could be made to expose sensitive information over the network. Software Description: - libetpan: Mail Framework for C Language Details: It was discovered that LibEtPan incorrectly handled STARTTLS when using IMAP, SMTP and POP3. A remote attacker could possibly use this issue to perform a response injection attack. (CVE-2020-15953) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libetpan-dev 1.6-1ubuntu0.1 libetpan17 1.6-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4598-1 CVE-2020-15953 Package Information: https://launchpad.net/ubuntu/+source/libetpan/1.6-1ubuntu0.1 . A security flaw in LibEtPan on Ubuntu 16.04 LTS could potentially leak critical data through network channels. Immediate updates are advised.. LibEtPan,vulnerability,security advisory,Ubuntu 16.04. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.