MGASA-2013-0296

Source
https://advisories.mageia.org/MGASA-2013-0296.html
Import Source
https://advisories.mageia.org/MGASA-2013-0296.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0296
Published
2013-10-09T22:27:52Z
Modified
2026-04-16T04:29:23.345345Z
Summary
Updated ssmtp package fixes security vulnerability
Details

It was reported that ssmtp, an extremely simple MTA to get mail off the system to a mail hub, did not perform x509 certificate validation when initiating a TLS connection to server. A rogue server could use this flaw to conduct man-in- the-middle attack, possibly leading to user credentials leak.

As a result, alterations may be required to the configuration if using TLS. The default ssmtp.conf now contains the lines below to load root certificates which should be created as ssmtp.conf.rpmnew if it has been altered.

IMPORTANT: Uncomment the following line if you use TLS authentication

TLSCAFile=/etc/pki/tls/certs/ca-bundle.crt

References
Credits

Affected packages

Mageia:2 / ssmtp

Package

Name
ssmtp
Purl
pkg:rpm/mageia/ssmtp?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.64-5.3.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0296.json"

Mageia:3 / ssmtp

Package

Name
ssmtp
Purl
pkg:rpm/mageia/ssmtp?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.64-8.3.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0296.json"