Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Exim could be made to allow response injection if it received a specially crafted response.. ========================================================================== Ubuntu Security Notice USN-6881-1 July 08, 2024 exim4 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Exim could be made to allow response injection if it received a specially crafted response. Software Description: - exim4: Exim is a mail transport agent Details: It was discovered that Exim did not enforce STARTTLS sync point on client side. An attacker could possibly use this issue to perform response injection during MTA SMTP sending. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS exim4 4.93-13ubuntu1.11 exim4-base 4.93-13ubuntu1.11 eximon4 4.93-13ubuntu1.11 Ubuntu 18.04 LTS exim4 4.90.1-1ubuntu1.10+esm4 Available with Ubuntu Pro exim4-base 4.90.1-1ubuntu1.10+esm4 Available with Ubuntu Pro eximon4 4.90.1-1ubuntu1.10+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS exim4 4.86.2-2ubuntu2.6+esm7 Available with Ubuntu Pro exim4-base 4.86.2-2ubuntu2.6+esm7 Available with Ubuntu Pro eximon4 4.86.2-2ubuntu2.6+esm7 Available with Ubuntu Pro Ubuntu 14.04 LTS exim4 4.82-3ubuntu2.4+esm8 Available with Ubuntu Pro exim4-base 4.82-3ubuntu2.4+esm8 Available with Ubuntu Pro eximon4 4.82-3ubuntu2.4+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6881-1 CVE-2021-38371 Package Information: https://launchpad.net/ubuntu/+source/exim4/4.93-13ubuntu1.11 . Exim has implemented a security patch addressing a response injection vulnerability that impacts various versions of Ubuntu. Discover additional details here.. Exim Update, Ubuntu Security, Mail Transport Agent, Security Patch. . Severity: Critical. LinuxSecurity.com Team
An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for evolution-data-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0949-1 Rating: moderate References: #1173910 #1174712 #1182882 Cross-References: CVE-2020-14928 CVE-2020-16117 CVSS scores: CVE-2020-14928 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2020-14928 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2020-16117 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-16117 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP2 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for evolution-data-server fixes the following issues: - CVE-2020-16117: Fix crash on malformed server response with minimal capabilities (bsc#1174712). - CVE-2020-14928: Response injection via STARTTLS in SMTP and POP3 (bsc#1173910). - Fix buffer overrun when parsing base64 data (bsc#1182882). This update for evolution-ews fixes the following issue: - Fix buffer overrun when parsing base64 data (bsc#1182882). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-WE-15-SP2-2021-949=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP2 (x86_64): evolution-data-server-3.34.4-3.3.1 evolution-data-server-debuginfo-3.34.4-3.3.1 evolution-data-server-debugsource-3.34.4-3.3.1 evolution-data-server-devel-3.34.4-3.3.1 evolution-ews-3.34.4-3.3.1 evolution-ews-debuginfo-3.34.4-3.3.1 evolution-ews-debugsource-3.34.4-3.3.1 libcamel-1_2-62-3.34.4-3.3.1 libcamel-1_2-62-debuginfo-3.34.4-3.3.1 libebackend-1_2-10-3.34.4-3.3.1 libebackend-1_2-10-debuginfo-3.34.4-3.3.1 libebook-1_2-20-3.34.4-3.3.1 libebook-1_2-20-debuginfo-3.34.4-3.3.1 libebook-contacts-1_2-3-3.34.4-3.3.1 libebook-contacts-1_2-3-debuginfo-3.34.4-3.3.1 libecal-2_0-1-3.34.4-3.3.1 libecal-2_0-1-debuginfo-3.34.4-3.3.1 libedata-book-1_2-26-3.34.4-3.3.1 libedata-book-1_2-26-debuginfo-3.34.4-3.3.1 libedata-cal-2_0-1-3.34.4-3.3.1 libedata-cal-2_0-1-debuginfo-3.34.4-3.3.1 libedataserver-1_2-24-3.34.4-3.3.1 libedataserver-1_2-24-debuginfo-3.34.4-3.3.1 libedataserverui-1_2-2-3.34.4-3.3.1 libedataserverui-1_2-2-debuginfo-3.34.4-3.3.1 typelib-1_0-Camel-1_2-3.34.4-3.3.1 typelib-1_0-EBook-1_2-3.34.4-3.3.1 typelib-1_0-EBookContacts-1_2-3.34.4-3.3.1 typelib-1_0-ECal-2_0-3.34.4-3.3.1 typelib-1_0-EDataServer-1_2-3.34.4-3.3.1 typelib-1_0-EDataServerUI-1_2-3.34.4-3.3.1 - SUSE Linux Enterprise Workstation Extension 15-SP2 (noarch): evolution-data-server-lang-3.34.4-3.3.1 evolution-ews-lang-3.34.4-3.3.1 References: https://www.suse.com/security/cve/CVE-2020-14928.html https://www.suse.com/security/cve/CVE-2020-16117.html https://bugzilla.suse.com/1173910 https://bugzilla.suse.com/1174712 https://bugzilla.suse.com/1182882 . SUSE patches resolve vulnerabilities in network-manager, boosting safety and correcting multiple defects. Learn more!. Suse Security, Evolution Data Update, Server Vulnerability Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for evolution-data-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0885-1 Rating: moderate References: #1173910 #1174712 #1182882 Cross-References: CVE-2020-14928 CVE-2020-16117 CVSS scores: CVE-2020-14928 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2020-14928 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2020-16117 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-16117 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for evolution-data-server fixes the following issues: - Fix buffer overrun when parsing base64 data (bsc#1182882). - CVE-2020-16117: Fix crash on malformed server response with minimal capabilities (bsc#1174712). - CVE-2020-14928: Response injection via STARTTLS in SMTP and POP3 (bsc#1173910). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2021-885=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libcamel-1_2-57-3.20.6-17.3.1 libcamel-1_2-57-debuginfo-3.20.6-17.3.1 libedataserver-1_2-21-3.20.6-17.3.1 libedataserver-1_2-21-debuginfo-3.20.6-17.3.1 References: https://www.suse.com/security/cve/CVE-2020-14928.html https://www.suse.com/security/cve/CVE-2020-16117.html https://bugzilla.suse.com/1173910 https://bugzilla.suse.com/1174712 https://bugzilla.suse.com/1182882 . A recent security patch resolves vulnerabilities in evolution-data-server, tackling concerns such as buffer overflow and injection vulnerabilities in responses.. SUSE Linux, evolution-data-server, Security Update, System Patch Management. . LinuxSecurity.com Team
An update for bogofilter, evolution, evolution-data-server, evolution-mapi, and openchange is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: evolution security and bug fix update Advisory ID: RHSA-2020:4649-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4649 Issue date: 2020-11-03 CVE Names: CVE-2020-14928 ==================================================================== 1. Summary: An update for bogofilter, evolution, evolution-data-server, evolution-mapi, and openchange is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Evolution is a GNOME application that provides integrated email, calendar, contact management, and communications functionality. The evolution-data-server packages provide a unified back end for applications which interact with contacts, tasks and calendar information. Evolution Data Server was originally developed as a back end for the Evolution information management application, but is now used by various other applications. OpenChange provides libraries to access Microsoft Exchange servers using native protocols. Security Fix(es): * evolution-data-server: Response injection via STARTTLS in SMTPand POP3 (CVE-2020-14928) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Evolution must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1825447 - openchange: does not rebuild with samba-4.11.2-7.el8 1836165 - Cannot type the date of a meeting 1836279 - Please upgrade to bogofilter 1.2.5 1857470 - CVE-2020-14928 evolution-data-server: Response injection via STARTTLS in SMTP and POP3 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: bogofilter-1.2.5-2.el8.src.rpm evolution-3.28.5-14.el8.src.rpm evolution-data-server-3.28.5-14.el8.src.rpm evolution-mapi-3.28.3-3.el8.src.rpm openchange-2.3-26.el8.src.rpm aarch64: bogofilter-1.2.5-2.el8.aarch64.rpm bogofilter-debuginfo-1.2.5-2.el8.aarch64.rpm bogofilter-debugsource-1.2.5-2.el8.aarch64.rpm evolution-3.28.5-14.el8.aarch64.rpm evolution-bogofilter-3.28.5-14.el8.aarch64.rpm evolution-bogofilter-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-data-server-3.28.5-14.el8.aarch64.rpm evolution-data-server-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-data-server-debugsource-3.28.5-14.el8.aarch64.rpm evolution-data-server-devel-3.28.5-14.el8.aarch64.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-debugsource-3.28.5-14.el8.aarch64.rpm evolution-mapi-3.28.3-3.el8.aarch64.rpm evolution-mapi-debuginfo-3.28.3-3.el8.aarch64.rpm evolution-mapi-debugsource-3.28.3-3.el8.aarch64.rpm evolution-pst-3.28.5-14.el8.aarch64.rpm evolution-pst-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-spamassassin-3.28.5-14.el8.aarch64.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.aarch64.rpm openchange-2.3-26.el8.aarch64.rpm openchange-client-debuginfo-2.3-26.el8.aarch64.rpm openchange-debuginfo-2.3-26.el8.aarch64.rpm openchange-debugsource-2.3-26.el8.aarch64.rpm noarch: evolution-data-server-langpacks-3.28.5-14.el8.noarch.rpm evolution-help-3.28.5-14.el8.noarch.rpm evolution-langpacks-3.28.5-14.el8.noarch.rpm evolution-mapi-langpacks-3.28.3-3.el8.noarch.rpm ppc64le: bogofilter-1.2.5-2.el8.ppc64le.rpm bogofilter-debuginfo-1.2.5-2.el8.ppc64le.rpm bogofilter-debugsource-1.2.5-2.el8.ppc64le.rpm evolution-3.28.5-14.el8.ppc64le.rpm evolution-bogofilter-3.28.5-14.el8.ppc64le.rpm evolution-bogofilter-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-data-server-3.28.5-14.el8.ppc64le.rpm evolution-data-server-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-data-server-debugsource-3.28.5-14.el8.ppc64le.rpm evolution-data-server-devel-3.28.5-14.el8.ppc64le.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-debugsource-3.28.5-14.el8.ppc64le.rpm evolution-mapi-3.28.3-3.el8.ppc64le.rpm evolution-mapi-debuginfo-3.28.3-3.el8.ppc64le.rpm evolution-mapi-debugsource-3.28.3-3.el8.ppc64le.rpm evolution-pst-3.28.5-14.el8.ppc64le.rpm evolution-pst-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-spamassassin-3.28.5-14.el8.ppc64le.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.ppc64le.rpm openchange-2.3-26.el8.ppc64le.rpm openchange-client-debuginfo-2.3-26.el8.ppc64le.rpm openchange-debuginfo-2.3-26.el8.ppc64le.rpm openchange-debugsource-2.3-26.el8.ppc64le.rpm s390x: bogofilter-1.2.5-2.el8.s390x.rpm bogofilter-debuginfo-1.2.5-2.el8.s390x.rpm bogofilter-debugsource-1.2.5-2.el8.s390x.rpm evolution-3.28.5-14.el8.s390x.rpm evolution-bogofilter-3.28.5-14.el8.s390x.rpm evolution-bogofilter-debuginfo-3.28.5-14.el8.s390x.rpm evolution-data-server-3.28.5-14.el8.s390x.rpm evolution-data-server-debuginfo-3.28.5-14.el8.s390x.rpm evolution-data-server-debugsource-3.28.5-14.el8.s390x.rpm evolution-data-server-devel-3.28.5-14.el8.s390x.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.s390x.rpm evolution-debuginfo-3.28.5-14.el8.s390x.rpm evolution-debugsource-3.28.5-14.el8.s390x.rpm evolution-mapi-3.28.3-3.el8.s390x.rpm evolution-mapi-debuginfo-3.28.3-3.el8.s390x.rpm evolution-mapi-debugsource-3.28.3-3.el8.s390x.rpm evolution-pst-3.28.5-14.el8.s390x.rpm evolution-pst-debuginfo-3.28.5-14.el8.s390x.rpm evolution-spamassassin-3.28.5-14.el8.s390x.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.s390x.rpm openchange-2.3-26.el8.s390x.rpm openchange-client-debuginfo-2.3-26.el8.s390x.rpm openchange-debuginfo-2.3-26.el8.s390x.rpm openchange-debugsource-2.3-26.el8.s390x.rpm x86_64: bogofilter-1.2.5-2.el8.x86_64.rpm bogofilter-debuginfo-1.2.5-2.el8.x86_64.rpm bogofilter-debugsource-1.2.5-2.el8.x86_64.rpm evolution-3.28.5-14.el8.x86_64.rpm evolution-bogofilter-3.28.5-14.el8.x86_64.rpm evolution-bogofilter-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-data-server-3.28.5-14.el8.i686.rpm evolution-data-server-3.28.5-14.el8.x86_64.rpm evolution-data-server-debuginfo-3.28.5-14.el8.i686.rpm evolution-data-server-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-data-server-debugsource-3.28.5-14.el8.i686.rpm evolution-data-server-debugsource-3.28.5-14.el8.x86_64.rpm evolution-data-server-devel-3.28.5-14.el8.i686.rpm evolution-data-server-devel-3.28.5-14.el8.x86_64.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.i686.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-debugsource-3.28.5-14.el8.x86_64.rpm evolution-mapi-3.28.3-3.el8.x86_64.rpm evolution-mapi-debuginfo-3.28.3-3.el8.x86_64.rpm evolution-mapi-debugsource-3.28.3-3.el8.x86_64.rpm evolution-pst-3.28.5-14.el8.x86_64.rpm evolution-pst-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-spamassassin-3.28.5-14.el8.x86_64.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.x86_64.rpm openchange-2.3-26.el8.i686.rpm openchange-2.3-26.el8.x86_64.rpm openchange-client-debuginfo-2.3-26.el8.i686.rpm openchange-client-debuginfo-2.3-26.el8.x86_64.rpm openchange-debuginfo-2.3-26.el8.i686.rpm openchange-debuginfo-2.3-26.el8.x86_64.rpm openchange-debugsource-2.3-26.el8.i686.rpm openchange-debugsource-2.3-26.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v.8): aarch64: evolution-bogofilter-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-data-server-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-data-server-debugsource-3.28.5-14.el8.aarch64.rpm evolution-data-server-perl-3.28.5-14.el8.aarch64.rpm evolution-data-server-tests-3.28.5-14.el8.aarch64.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-debugsource-3.28.5-14.el8.aarch64.rpm evolution-devel-3.28.5-14.el8.aarch64.rpm evolution-pst-debuginfo-3.28.5-14.el8.aarch64.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.aarch64.rpm noarch: evolution-data-server-doc-3.28.5-14.el8.noarch.rpm ppc64le: evolution-bogofilter-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-data-server-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-data-server-debugsource-3.28.5-14.el8.ppc64le.rpm evolution-data-server-perl-3.28.5-14.el8.ppc64le.rpm evolution-data-server-tests-3.28.5-14.el8.ppc64le.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-debugsource-3.28.5-14.el8.ppc64le.rpm evolution-devel-3.28.5-14.el8.ppc64le.rpm evolution-pst-debuginfo-3.28.5-14.el8.ppc64le.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.ppc64le.rpm s390x: evolution-bogofilter-debuginfo-3.28.5-14.el8.s390x.rpm evolution-data-server-debuginfo-3.28.5-14.el8.s390x.rpm evolution-data-server-debugsource-3.28.5-14.el8.s390x.rpm evolution-data-server-perl-3.28.5-14.el8.s390x.rpm evolution-data-server-tests-3.28.5-14.el8.s390x.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.s390x.rpm evolution-debuginfo-3.28.5-14.el8.s390x.rpm evolution-debugsource-3.28.5-14.el8.s390x.rpm evolution-devel-3.28.5-14.el8.s390x.rpm evolution-pst-debuginfo-3.28.5-14.el8.s390x.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.s390x.rpm x86_64: evolution-bogofilter-debuginfo-3.28.5-14.el8.i686.rpm evolution-bogofilter-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-data-server-debuginfo-3.28.5-14.el8.i686.rpm evolution-data-server-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-data-server-debugsource-3.28.5-14.el8.i686.rpm evolution-data-server-debugsource-3.28.5-14.el8.x86_64.rpm evolution-data-server-perl-3.28.5-14.el8.x86_64.rpm evolution-data-server-tests-3.28.5-14.el8.i686.rpm evolution-data-server-tests-3.28.5-14.el8.x86_64.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.i686.rpm evolution-data-server-tests-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-debuginfo-3.28.5-14.el8.i686.rpm evolution-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-debugsource-3.28.5-14.el8.i686.rpm evolution-debugsource-3.28.5-14.el8.x86_64.rpm evolution-devel-3.28.5-14.el8.i686.rpm evolution-devel-3.28.5-14.el8.x86_64.rpm evolution-pst-debuginfo-3.28.5-14.el8.i686.rpm evolution-pst-debuginfo-3.28.5-14.el8.x86_64.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.i686.rpm evolution-spamassassin-debuginfo-3.28.5-14.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-14928 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX6I1q9zjgjWX9erEAQiwoQ//buEUtanTCbZTJzlnxxIelsIxRohRRi0f KcP8B0im8WJjk4Ie4knSyVn4xi6dhouiDviZGgk4DmVSaV53MKgK6slmnhw4Y6vk +At+mNttFlkE/0GGKsX3Gp+FYdFyrsAqg9pntMvexv7zsehGpBRBh27IHeAchdvr 5UUWk64r4GdAquArB51WdpocISh5B93kqi6y/WBL1lFpElnmgsc99FcaQtD7FzIC YFfBFLiejoPtwE9of6QIahr6EPg4cRiaVSe0MUDWy+ouesGd1M8fClmjWeswcpnY mc0CpKXsbqwa9oZFbFfQ+YC70uBX/+Z5b0nPUSrP+OZO8yyeeYIdEpT2/mLPiDFE cjo8q0fmuKquqE2jBdn+8Kx9h7S4x2RLnyg+GngmC+UYYrFdUyCUuH2/f6ezo3Fe 2bh5FyYIDh+81ljY3dItvc/cSeWGvHj4mVxaCMq5wQnbzXP9SlqGQncLRrK9PhA2 6TNCwz7nQDiW5aDoeKo7s/oWXsGI1/uBwjyWOWU06GQ8QJMcyHWbfOBUef6SpNzk T4Rl+98uKecem/xJIZUVeduCbwxsSOEz7iUVI39XNB9NJofafRUjzlQqI55Lb49A Ma2nrRleaF1F6ohQ/eF6dEQuET95MtBftKOfMN0NrSFEmSJo+pSb4DIrqRA5sC05 A0+T0YkAsF0=IWMO -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A potential IMAP Man-in-the-Middle attack via a PREAUTH response (CVE-2020-14093). Mutt was ignoring an expired certificate and was proceeding with a connection (CVE-2020-14154). . MGASA-2020-0357 - Updated mutt packages fix security vulnerabilities Publication date: 02 Sep 2020 URL: https://advisories.mageia.org/MGASA-2020-0357.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-14093, CVE-2020-14954 A potential IMAP Man-in-the-Middle attack via a PREAUTH response (CVE-2020-14093). Mutt was ignoring an expired certificate and was proceeding with a connection (CVE-2020-14154). A response injection due to a STARTTLS buffering issue which was affecting IMAP, SMTP, and POP3 (CVE-2020-14954). References: - https://bugs.mageia.org/show_bug.cgi?id=26852 - https://lists.debian.org/debian-security-announce/2020/msg00111.html - https://lists.debian.org/debian-security-announce/2020/msg00112.html - - https://www.cve.org/CVERecord?id=CVE-2020-14093 - https://www.cve.org/CVERecord?id=CVE-2020-14954 SRPMS: - 7/core/mutt-1.11.4-1.3.mga7 . Mageia 2020-0358 delivers essential enhancements for Vim tackling security risks and buffer overflow issues.. Mutt Security Update, Mageia Patch, IMAP Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection". (CVE-2020-14928) . MGASA-2020-0351 - Updated evolution-data-server packages fix security vulnerabilities Publication date: 28 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0351.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-14928, CVE-2020-16117 evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection". (CVE-2020-14928) In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server. (CVE-2020-16117) References: - https://bugs.mageia.org/show_bug.cgi?id=26962 - https://lists.debian.org/debian-security-announce/2020/msg00131.html - https://lists.debian.org/debian-security-announce/2020/msg00131.html - https://lists.debian.org/debian-lts-announce/2020/07/msg00012.html - https://lists.debian.org/debian-lts-announce/2020/08/msg00005.html - https://www.cve.org/CVERecord?id=CVE-2020-14928 - https://www.cve.org/CVERecord?id=CVE-2020-16117 SRPMS: - 7/core/evolution-data-server-3.32.2-1.2.mga7 . Revised evolution-data-server components address significant challenges impacting SMTP and POP3 linkages within Mageia.. evolution-data-server, security update, Mageia advisory, STARTTLS issue. . Severity: Critical. LinuxSecurity.com Team
A security flaw was found on libetpan which may allow malicious attacker to inject additional responses or mimic whole sessions. This vulnerability is now assined as CVE-2020-15953. This new rpm should fix this issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-44e52ef729 2020-08-19 01:01:08.078920 --------------------------------------------------------------------------------Name : libetpan Product : Fedora 31 Version : 1.9.3 Release : 3.fc31 URL : Summary : Portable, efficient middle-ware for different kinds of mail access Description : The purpose of this mail library is to provide a portable, efficient middle-ware for different kinds of mail access. When using the drivers interface, the interface is the same for all kinds of mail access, remote and local mailboxes. --------------------------------------------------------------------------------Update Information: A security flaw was found on libetpan which may allow malicious attacker to inject additional responses or mimic whole sessions. This vulnerability is now assined as CVE-2020-15953. This new rpm should fix this issue. --------------------------------------------------------------------------------ChangeLog: * Mon Aug 10 2020 Mamoru TASAKA - 1.9.3-3 - Address CVE-2020-15953 (bug 1861068) --------------------------------------------------------------------------------References: [ 1 ] Bug #1861071 - CVE-2020-15953 libetpan: response injection via STARTTLS in IMAP [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1861071 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-44e52ef729' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A security flaw was found on libetpan which may allow malicious attacker to inject additional responses or mimic whole sessions. This vulnerability is now assined as CVE-2020-15953. This new rpm should fix this issue.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-13ae5f7221 2020-08-19 00:51:10.926437 --------------------------------------------------------------------------------Name : libetpan Product : Fedora 32 Version : 1.9.4 Release : 4.fc32 URL : Summary : Portable, efficient middle-ware for different kinds of mail access Description : The purpose of this mail library is to provide a portable, efficient middle-ware for different kinds of mail access. When using the drivers interface, the interface is the same for all kinds of mail access, remote and local mailboxes. --------------------------------------------------------------------------------Update Information: A security flaw was found on libetpan which may allow malicious attacker to inject additional responses or mimic whole sessions. This vulnerability is now assined as CVE-2020-15953. This new rpm should fix this issue. --------------------------------------------------------------------------------ChangeLog: * Mon Aug 10 2020 Mamoru TASAKA - 1.9.4-4 - Address CVE-2020-15953 (bug 1861068) * Tue Jul 28 2020 Fedora Release Engineering - 1.9.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1861071 - CVE-2020-15953 libetpan: response injection via STARTTLS in IMAP [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1861071 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-13ae5f7221' at the command line. For more information, refer to thednf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.