Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in UW IMAP
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in UW IMAP
ID: USN-4160-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 19.04
Datum: Di, 22. Oktober 2019, 07:22
Referenzen: https://launchpad.net/ubuntu/+source/uw-imap/8:2007f~dfsg-4+deb8u1build0.16.04.1
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19518
Applikationen: UW IMAP Server

Originalnachricht


--===============5399032506724925286==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-nWI2kmp/Ry2/NgwF19yk"


--=-nWI2kmp/Ry2/NgwF19yk
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4160-1
October 21, 2019

uw-imap vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

UW IMAP could be made to execute programs if it received specially crafted
input.

Software Description:
- uw-imap: c-client library for mail protocols - library files

Details:

It was discovered that UW IMAP incorrectly handled inputs. A remote attacker
could possibly use this issue to execute arbitrary OS commands.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
libc-client2007e 8:2007f~dfsg-5ubuntu0.19.04.2
mlock 8:2007f~dfsg-5ubuntu0.19.04.2
uw-mailutils 8:2007f~dfsg-5ubuntu0.19.04.2

Ubuntu 18.04 LTS:
libc-client2007e 8:2007f~dfsg-5ubuntu0.18.04.2
mlock 8:2007f~dfsg-5ubuntu0.18.04.2
uw-mailutils 8:2007f~dfsg-5ubuntu0.18.04.2

Ubuntu 16.04 LTS:
libc-client2007e 8:2007f~dfsg-4+deb8u1build0.16.04.1
mlock 8:2007f~dfsg-4+deb8u1build0.16.04.1
uw-mailutils 8:2007f~dfsg-4+deb8u1build0.16.04.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4160-1
CVE-2018-19518

Package Information:
https://launchpad.net/ubuntu/+source/uw-imap/8:2007f~dfsg-5ubuntu0.19.04.2
https://launchpad.net/ubuntu/+source/uw-imap/8:2007f~dfsg-5ubuntu0.18.04.2

https://launchpad.net/ubuntu/+source/uw-imap/8:2007f~dfsg-4+deb8u1build0.16.04.1

--=-nWI2kmp/Ry2/NgwF19yk
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEECtyyz6azUy6AZBzSkGeI6zGnN/8FAl2uIz4ACgkQkGeI6zGn
N//74RAApimChMnhpDMIug78RlUUF6K8SFMCxtFleQIi2z6tuji59QDCIDC5nJJY
wxRy6e+y0xGU/GCYNNO9L6Qa+O8rsmCiFbdh46Tr1j6MOzCD8RtLYF8VgLTD+gbE
yS92ARcoHydt1nhK8eiCOWsWSej6WEsZ63tZck4e83y0JS/zUPQ1WyIZMcMLPkqe
1f0hQ0ezVvTsqaFT29udtMyIW2jrX/MvzSQnggKthwvzzKlhqLKorInLO/gxAXB8
udGgsD8wZDaZVmw6gkUCBT62h63ZrB4EQIl2hkJi1566OrriOXNa0KnFUnVYzBAf
yAUsSwYJo3mLzf1svdaVxEHrUlQLRhiR6mjZ2MqUnMTUyEFWSpJ4usgxVY30PqYt
fbDgQlqCebRPIy82ZNWeI7MVrrdBloYekWERQsCihwM677lU9lCgJvpl3O1vYE8W
CVBToVp4vSesDEZXog5XvDtocTHbsyj3c5pbjnavI7CSlRGqTv7o4S0R7RpYxYy/
PyRGP7cQNYxf9BIxMoAHml7RN8VrsrOsZe/maaguc8527nJdY3zzlX+jFM7qGvm/
uTUSUL9RmRc58DvbpZApU6L2aCuw6xBD0eagCCSLVtVfmWvqvamZXHyCM4NNsJTg
zU4/mPczJqHq1Oj3XiCZ8B4jhrrDz97tkuRDbXm0vYTjZ9bHnHo=
=zlWq
-----END PGP SIGNATURE-----

--=-nWI2kmp/Ry2/NgwF19yk--



--===============5399032506724925286==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============5399032506724925286==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung