MGASA-2020-0366

Source
https://advisories.mageia.org/MGASA-2020-0366.html
Import Source
https://advisories.mageia.org/MGASA-2020-0366.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0366
Related
Published
2020-09-15T11:45:52Z
Modified
2020-09-15T11:14:29Z
Summary
Updated libetpan packages fix a security vulnerability
Details

LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection". (CVE-2020-15953).

References
Credits

Affected packages

Mageia:7 / libetpan

Package

Name
libetpan
Purl
pkg:rpm/mageia/libetpan?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.3-1.1.mga7

Ecosystem specific

{
    "section": "core"
}