Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in dovecot
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in dovecot
ID: USN-1295-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.10
Datum: Do, 8. Dezember 2011, 23:56
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4318
Applikationen: dovecot

Originalnachricht


--===============8092044859922556861==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-YlcFsCymybc3Y+vKdIt+"


--=-YlcFsCymybc3Y+vKdIt+
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1295-1
December 08, 2011

dovecot vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10

Summary:

Dovecot could be made to expose sensitive information over the network.

Software Description:
- dovecot: IMAP and POP3 email server

Details:

It was discovered that Dovecot incorrectly validated certificate hostnames
when being used as a POP3 and IMAP proxy. If a remote attacker were able to
perform a man-in-the-middle attack, this flaw could be exploited to view
sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
dovecot-common 1:2.0.13-1ubuntu3.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1295-1
CVE-2011-4318

Package Information:
https://launchpad.net/ubuntu/+source/dovecot/1:2.0.13-1ubuntu3.2



--ÒlcFsCymybc3Y+vKdIt+
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJO4RoKAAoJEGVp2FWnRL6TNXMP/1K9yCveJ2w5CTmqHJ50yDAm
bM83nN0PuorPj5o2ju/kGoZYvo6MBE5LBp5OdwQmCtgWEMdZSc/R9PdasUttyTf1
SFN8pkafHOt3Yhf6QtzMzSFNx/1AEUvwHOJdd/bECg+FQRWASMz2jfrJvcrOr1nb
ntiUawU4qq+OSp1Z7WTZd6TKph5eNUt9f7Rkk1MgC48opSffYvZEF1Avtwruik2O
RaEYAR6kgZeHGuuNTPz3nYyiQgowzqCq/4ejAs9C7gyQ15QkV5gW0h9/SjsuYvBS
owVmafHXcbeXQN89coi+52Bsx74t/Ny9jEsRC/5eZnsRy7FECjmEnVtPMKgR5wws
RygEYsggsnlxrkehHZQ5ejo2RCOItAw34mdL8izdxIBD1BBjMZnQz04RVIZHNq9P
R4bDHJP4WeI9yQcOZFTA8FIlPIXIox2ZOtHnV1YpF8CZOwuiHT9YQ5MtawfJ/AfH
+Ml73F9h/q46a3Wu5jFRXPLBgMz1l1TCIYdMHtJRmMlF/vKHtN7hkjUsfeFkEYWO
QhqJ+rxJd84fF56mCWwZ/DYcm5vb55NOkCsH5PzBZd3fAz0tgnbWb6NkCuVOrtKU
4lKXodPgrzuChYxg+s1QUKdWTUdunmAhe7QOqaWRe4kOM9ZAslSE+dVVobzg+xjY
tfrB3BbLWPEKUMoXbikL
=NvNC
-----END PGP SIGNATURE-----

--=-YlcFsCymybc3Y+vKdIt+--



--===============8092044859922556861==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8092044859922556861==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung