Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass. . Arch Linux Security Advisory ASA-201902-22 ========================================= Severity: High Date : 2019-02-17 CVE-ID : CVE-2019-8337 Package : msmtp Type : certificate verification bypass Remote : Yes Link : https://security.archlinux.org/AVG-905 Summary ====== The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass. Resolution ========= Upgrade to 1.8.3-1. # pacman -Syu "msmtp> =1.8.3-1" The problem has been fixed upstream in version 1.8.3. Workaround ========= None. Description ========== In msmtp 1.8.2, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. Impact ===== The default configuration would omit certification verification. References ========= https://marlam.de/msmtp/news/ https://security.archlinux.org/CVE-2019-8337 . The Debian Security Advisory DSA-2021-55 highlights critical vulnerabilities in `libxml2`, stressing the need for secure XML parsing and risks from malformed input. Arch Linux, msmtp, certificate issue, security advisory. . LinuxSecurity.com Team
An error in the hostname matching in msmtp might enable remote attackers to conduct man-in-the-middle attacks.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201206-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: msmtp: X.509 NULL spoofing vulnerability Date: June 25, 2012 Bugs: #293647 ID: 201206-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An error in the hostname matching in msmtp might enable remote attackers to conduct man-in-the-middle attacks. Background ========= msmtp is an SMTP client and SMTP plugin for mail user agents such as Mutt. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-mta/msmtp < 1.4.19 > = 1.4.19 Description ========== A vulnerability have been discovered in msmtp. Please review the CVE identifier referenced below for details. Impact ===== A remote attacker might employ a specially crafted certificate to conduct man-in-the-middle attacks on SSL connections made using msmtp. Workaround ========= There is no known workaround at this time. Resolution ========= All msmtp users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-mta/msmtp-1.4.19" References ========= [ 1 ] CVE-2009-3942 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3942 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201206-34 Concerns? ======== Security is a primary focusof Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.