openSUSE-SU-2021:4018-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:4018-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2021:4018-1
Related
Published
2021-12-14T07:58:47Z
Modified
2021-12-14T07:58:47Z
Summary
Security update for fetchmail
Details

This update for fetchmail fixes the following issues:

  • CVE-2021-36386: Fixed DoS or information disclosure in some configurations (bsc#1188875).
  • CVE-2021-39272: Fixed STARTTLS session encryption bypassing (fetchmail-SA-2021-02) (bsc#1190069).

  • Update to 6.4.22 (bsc#1152964, jsc#SLE-18159, jsc#SLE-17903, jsc#SLE-18059)

  • Remove all python2 dependencies (bsc#1190896).
  • De-hardcode /usr/lib path for launch executable (bsc#1174075).
  • Added hardening to systemd service(s) (bsc#1181400).
References

Affected packages

openSUSE:Leap 15.3 / fetchmail

Package

Name
fetchmail
Purl
purl:rpm/suse/fetchmail&distro=openSUSE%20Leap%2015.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.22-20.20.1

Ecosystem specific

{
    "binaries": [
        {
            "fetchmail": "6.4.22-20.20.1",
            "fetchmailconf": "6.4.22-20.20.1"
        }
    ]
}