UbuntuUpdates.org

Package "libetpan17"

Name: libetpan17

Description:

mail handling library

Latest version: 1.6-1ubuntu0.1
Release: xenial (16.04)
Level: security
Repository: universe
Head package: libetpan
Homepage: http://libetpan.sourceforge.net/libetpan

Links


Download "libetpan17"


Other versions of "libetpan17" in Xenial

Repository Area Version
base universe 1.6-1build1
updates universe 1.6-1ubuntu0.1

Changelog

Version: 1.6-1ubuntu0.1 2020-10-22 14:06:19 UTC

  libetpan (1.6-1ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: response injection in STARTTLS
    - debian/patches/CVE-2020-15953-1.patch: detect extra data after
      STARTTLS response and exit
    - debian/patches/CVE-2020-15953-2.patch: detect extra data after
      STARTTLS responses in SMTP and POP3 and exit
    - CVE-2020-15953

 -- Emilia Torino <email address hidden> Wed, 21 Oct 2020 12:04:42 -0300

CVE-2020-15953 LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. Whe



About   -   Send Feedback to @ubuntu_updates