In libEtPan, a mail library, a STARTTLS response injection was discovered that affects IMAP, SMTP, and POP3. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2329-1
Update to new upstream version 0.54 fixing a crash (NULL pointer dereference) in the mail message header parser. Note: There is no application in Fedora using libetpan library for which such crash could be considered a security issue. This can only be a security sensitive issue for some 3rd party, not packages applications.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-5480 2008-06-26 02:39:29 --------------------------------------------------------------------------------Name : libetpan Product : Fedora 8 Version : 0.54 Release : 1.fc8 URL : Summary : Portable, efficient middleware for different kinds of mail access Description : The purpose of this mail library is to provide a portable, efficient middleware for different kinds of mail access. When using the drivers interface, the interface is the same for all kinds of mail access, remote and local mailboxes. --------------------------------------------------------------------------------Update Information: Update to new upstream version 0.54 fixing a crash (NULL pointer dereference) in the mail message header parser. Note: There is no application in Fedora using libetpan library for which such crash could be considered a security issue. This can only be a security sensitive issue for some 3rd party, not packages applications. --------------------------------------------------------------------------------ChangeLog: * Tue Jun 17 2008 Andreas Bierfert - 0.54-1 - version upgrade - fix #451025 * Mon Feb 11 2008 Andreas Bierfert - 0.52-5 - Rebuilt for gcc43 * Sat Jan 5 2008 Andreas Bierfert - 0.52-4 - fix #342021 multiarch * Thu Dec 6 2007 Andreas Bierfert - 0.52-3 - bump * Mon Nov 19 2007 Andreas Bierfert - 0.52-2 - bump --------------------------------------------------------------------------------References: [ 1 ] Bug #451025 - crash in mailimf_group_parse due to a colon in To: address https://bugzilla.redhat.com/show_bug.cgi?id=451025 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update libetpan' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.