An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session.
{
"binaries": [
{
"binary_name": "courier-base",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-faxmail",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-imap",
"binary_version": "4.10.0-20120615-1ubuntu7"
},
{
"binary_name": "courier-imap-ssl",
"binary_version": "4.10.0-20120615-1ubuntu7"
},
{
"binary_name": "courier-ldap",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-maildrop",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-mlm",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-mta",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-mta-ssl",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-pcp",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-pop",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-pop-ssl",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-ssl",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "courier-webadmin",
"binary_version": "0.68.2-1ubuntu7"
},
{
"binary_name": "sqwebmail",
"binary_version": "0.68.2-1ubuntu7"
}
]
}
{
"binaries": [
{
"binary_name": "courier-base",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-faxmail",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-imap",
"binary_version": "4.18.1+0.78.0-2ubuntu2"
},
{
"binary_name": "courier-imap-ssl",
"binary_version": "4.18.1+0.78.0-2ubuntu2"
},
{
"binary_name": "courier-ldap",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-maildrop",
"binary_version": "2.9.1+0.78.0-2ubuntu2"
},
{
"binary_name": "courier-mlm",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-mta",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-mta-ssl",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-pcp",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-pop",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-pop-ssl",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-ssl",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "courier-webadmin",
"binary_version": "0.78.0-2ubuntu2"
},
{
"binary_name": "sqwebmail",
"binary_version": "5.9.0+0.78.0-2ubuntu2"
}
]
}
{
"binaries": [
{
"binary_name": "courier-base",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "courier-faxmail",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "courier-imap",
"binary_version": "5.0.6+1.0.6-1build2"
},
{
"binary_name": "courier-ldap",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "courier-mlm",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "courier-mta",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "courier-pcp",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "courier-pop",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "courier-webadmin",
"binary_version": "1.0.6-1build2"
},
{
"binary_name": "sqwebmail",
"binary_version": "6.0.0+1.0.6-1build2"
}
]
}
{
"binaries": [
{
"binary_name": "courier-base",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "courier-faxmail",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "courier-imap",
"binary_version": "5.0.13+1.0.16-3build3"
},
{
"binary_name": "courier-ldap",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "courier-mlm",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "courier-mta",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "courier-pcp",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "courier-pop",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "courier-webadmin",
"binary_version": "1.0.16-3build3"
},
{
"binary_name": "sqwebmail",
"binary_version": "6.0.5+1.0.16-3build3"
}
]
}
{
"binaries": [
{
"binary_name": "courier-base",
"binary_version": "1.4.1-3"
},
{
"binary_name": "courier-faxmail",
"binary_version": "1.4.1-3"
},
{
"binary_name": "courier-imap",
"binary_version": "5.2.11+1.4.1-3"
},
{
"binary_name": "courier-ldap",
"binary_version": "1.4.1-3"
},
{
"binary_name": "courier-mlm",
"binary_version": "1.4.1-3"
},
{
"binary_name": "courier-mta",
"binary_version": "1.4.1-3"
},
{
"binary_name": "courier-pcp",
"binary_version": "1.4.1-3"
},
{
"binary_name": "courier-pop",
"binary_version": "1.4.1-3"
},
{
"binary_name": "courier-webadmin",
"binary_version": "1.4.1-3"
},
{
"binary_name": "sqwebmail",
"binary_version": "6.2.9+1.4.1-3"
}
]
}