Updated cyrus-imapd-2.2 has been released for Debian GNU/Linux
- -------------------------------------------------------------------------- Debian Security Advisory DSA-2318-1 security@debian.org http://www.debian.org/security/ Nico Golde Oct 6, 2011 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : cyrus-imapd-2.2 Vulnerability : multiple Problem type : remote Debian-specific: no Debian bug : none CVE IDs : CVE-2011-3372 CVE-2011-3208 Multiple security issues have been discovered in cyrus-imapd, a highly scalable mail system designed for use in enterprise environments. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-3208 Coverity discovered a stack-based buffer overflow in the NNTP server implementation (nttpd) of cyrus-imapd. An attacker can exploit this flaw via several crafted NNTP commands to execute arbitrary code. CVE-2011-3372 Stefan Cornelius of Secunia Research discovered that the command processing of the NNTP server implementation (nttpd) of cyrus-imapd is not properly implementing access restrictions for certain commands and is not checking for a complete, successful authentication. An attacker can use this flaw to bypass access restrictions for some commands and, e.g. exploit CVE-2011-3208 without proper authentication. For the oldstable distribution (lenny), this problem has been fixed in version 2.2_2.2.13-14+lenny5. For the stable distribution (squeeze), this problem has been fixed in version 2.2_2.2.13-19+squeeze2. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in cyrus-imapd-2.4 version 2.4.12-1. We recommend that you upgrade your cyrus-imapd-2.2 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/
This entry was posted
on 3:06 PM
.
Archives
-
▼
2011
(171)
-
▼
October
(31)
- Droid Razr goes on sale as Mot unveils Fire XT sma...
- Samsung Galaxy S II Android Smartphone Review
- Cortex-A9/FPGA combo SoC gains open source Linux p...
- Linux 3.1 released with NFC support
- Linux 3.1 Enhances Sandy Bridge, Preps For Ivy Bridge
- ARM will detail Cortex-A7 at this week's TechCon
- Microsoft collects license fees on 50% of Android ...
- Kloxo 6.1.7 Beta 2 released
- Kloxo 6.1.7 Beta 3 released
- Compact PC sports three Mini PCI slots
- Kdelibs Security Update for CentOS
- Android 4.0 unveiled with new unified UI, face rec...
- Ubuntu 11.10 Oneiric Ocelot Review: First Real Ste...
- The Perfect Server - Ubuntu 11.10 (ISPConfig 3)
- Core-based PICMG 1.3 SBC supports 14 USB ports
- Ubuntu 11.10 Server tames cloud with Juju, Opensta...
- CompatDB Updates 10/14/11
- Apple wins preliminary Galaxy Tab 10.1 ban in Aust...
- Editing Images With Pinta
- Latest MyTouch phones feature help wizards
- Multiserver Setup With Dedicated Web, Email, DNS &...
- Cyrus-imapd-2.2 security update for Debian
- Intel unveils smaller, power-sipping Atoms
- Red Hat Enterprise Linux 6.2 Beta
- 20 ways to break Linux
- CompatDB Updates 10/05/11
- Puppet security update for Debian
- CompatDB Updates 10/03/11
- Kloxo 6.1.7 pre-release 5 (20110928)
- ThinkPad Tablet holds its own against iPad in ente...
- Revised seven-inch Galaxy Tab is thinner, lighter,...
-
▼
October
(31)