Mangelnde Rechteprüfung in Dovecot (Aktualisierung)
ID: | USN-3881-2 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 ESM |
Datum: | Di, 5. Februar 2019, 21:42 |
Referenzen: | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3814 |
Applikationen: | dovecot |
Update von: | Preisgabe von Informationen in Dovecot |
Originalnachricht |
|
--===============1013515329443324578== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="=-Rt+TCxRZ+tvzFYNX8Dwy" --=-Rt+TCxRZ+tvzFYNX8Dwy Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-3881-2 February 05, 2019 dovecot vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Dovecot could be made to expose sensitive information over the network. Software Description: - dovecot: IMAP and POP3 email server Details: USN-3881-1 fixed a vulnerability in Dovecot. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Dovecot incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: dovecot-core 1:2.0.19-0ubuntu2.6 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/usn/usn-3881-2 https://usn.ubuntu.com/usn/usn-3881-1 CVE-2019-3814 --=-Rt+TCxRZ+tvzFYNX8Dwy Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCAAGBQJcWbzQAAoJEEW851uECx9pzfoP/115udANjvzAYNHJvfR7H9B/ YYWOyOwuIvPOhVyaHmxWqfSEWOJ6/LSVg2EtO7RZp6TuWL/MVe/nz8glfuRvR9Wc zf8ensSVk1ugmHnCIb7Pg4R7D/VEcdGsvLe86/XlI5MOiVtUUqwQcevCmhopdCx+ YkWLd+IqY6sJwwkKZS/O8rGMJKQ8VNIBTv8dyQ4HdXBP5FYcXumkFG7gRBa0XUOR ESMg5j0iEu90PRnUIxd5jsQkTJ2UUZxJ0WWheBON4KbCTujZDJ8Z7tggsaOQdHB7 zoWA8Rcu9SbdR7IBKOo15T2Jje/vWbQZ5luyrbD7CZcEJhQeiSKWT+mJgzboveqU M5OPMIdKCakDMuuBKCjNPMRhs8KRFGBVLL9XQqD2lGqCK4i+MsalmP1TEW3LyoyB Xhd3/STZfhvcfUxVpRQdOIZuxnKAzLR89FB0W84/6U1sSljBRRzpEYveBc/px0HS Ha/P8YYCHys2IXQF3hgOuK49Qp5aIj9mE2lqWisL8xRlY2PtHz03BCdob4y5xOLJ /KGUTz7EkZr8GAQyGCGQo1HyPj6sbGPsYW2pGp65uPzRMqkkT/9PXDQZDrC5hjNT 77xW+xpH0PDk3/WICLqWlxuhmI8pt5rODkJycahEL1jK0YaqkKEuzjvlT3I8dDxk 1PPEPAUyxLX93n6KjaDm =zYDD -----END PGP SIGNATURE----- --=-Rt+TCxRZ+tvzFYNX8Dwy-- --===============1013515329443324578== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK --===============1013515329443324578==-- |