openSUSE-SU-2021:1591-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1591-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2021:1591-1
Related
Published
2021-12-17T11:06:33Z
Modified
2021-12-17T11:06:33Z
Summary
Security update for fetchmail
Details

This update for fetchmail fixes the following issues:

  • CVE-2021-36386: Fixed DoS or information disclosure in some configurations (bsc#1188875).
  • CVE-2021-39272: Fixed STARTTLS session encryption bypassing (fetchmail-SA-2021-02) (bsc#1190069).

  • Update to 6.4.22 (bsc#1152964, jsc#SLE-18159, jsc#SLE-17903, jsc#SLE-18059)

  • Remove all python2 dependencies (bsc#1190896).
  • De-hardcode /usr/lib path for launch executable (bsc#1174075).
  • Added hardening to systemd service(s) (bsc#1181400).

This update was imported from the SUSE:SLE-15:Update update project.

References

Affected packages

openSUSE:Leap 15.2 / fetchmail

Package

Name
fetchmail
Purl
purl:rpm/suse/fetchmail&distro=openSUSE%20Leap%2015.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.22-lp152.6.12.1

Ecosystem specific

{
    "binaries": [
        {
            "fetchmail": "6.4.22-lp152.6.12.1",
            "fetchmailconf": "6.4.22-lp152.6.12.1"
        }
    ]
}