MGASA-2014-0127

Source
https://advisories.mageia.org/MGASA-2014-0127.html
Import Source
https://advisories.mageia.org/MGASA-2014-0127.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0127
Upstream
  • CVE-2013-4279
Published
2014-03-12T16:18:38Z
Modified
2026-04-16T06:26:25.714388811Z
Summary
Updated imapsync packages fix an information disclosure
Details

Updated imapsync package fixes security vulnerability:

Imapsync, by default, runs a "release check" when executed, which causes imapsync to connect to http://imapsync.lamiral.info and send information about the version of imapsync, the operating system and perl (CVE-2013-4279).

The imapsync package has been patched to disable this feature.

References
Credits

Affected packages

Mageia:3 / imapsync

Package

Name
imapsync
Purl
pkg:rpm/mageia/imapsync?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.584-1.1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0127.json"

Mageia:4 / imapsync

Package

Name
imapsync
Purl
pkg:rpm/mageia/imapsync?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.584-1.1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0127.json"