|
|
Subscribe / Log in / New account

Ubuntu alert USN-4429-1 (evolution-data-server)

From:  Marc Deslauriers <marc.deslauriers@canonical.com>
To:  "ubuntu-security-announce@lists.ubuntu.com" <ubuntu-security-announce@lists.ubuntu.com>
Subject:  [USN-4429-1] Evolution Data Server vulnerability
Date:  Wed, 22 Jul 2020 10:24:49 -0400
Message-ID:  <99f5d4f0-0f42-33f2-3cd0-9f44f48470e4@canonical.com>

========================================================================== Ubuntu Security Notice USN-4429-1 July 22, 2020 evolution-data-server vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Evolution Data Server could be made to expose sensitive information over the network. Software Description: - evolution-data-server: Evolution suite data server Details: It was discovered that Evolution Data Server incorrectly handled STARTTLS when using SMTP and POP3. A remote attacker could possibly use this issue to perform a response injection attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: evolution-data-server 3.36.3-0ubuntu1.1 evolution-data-server-common 3.36.3-0ubuntu1.1 libcamel-1.2-62 3.36.3-0ubuntu1.1 libebackend-1.2-10 3.36.3-0ubuntu1.1 libedataserver-1.2-24 3.36.3-0ubuntu1.1 Ubuntu 18.04 LTS: evolution-data-server 3.28.5-0ubuntu0.18.04.3 evolution-data-server-common 3.28.5-0ubuntu0.18.04.3 libcamel-1.2-61 3.28.5-0ubuntu0.18.04.3 libebackend-1.2-10 3.28.5-0ubuntu0.18.04.3 libedataserver-1.2-23 3.28.5-0ubuntu0.18.04.3 Ubuntu 16.04 LTS: evolution-data-server 3.18.5-1ubuntu1.3 evolution-data-server-common 3.18.5-1ubuntu1.3 libcamel-1.2-54 3.18.5-1ubuntu1.3 libebackend-1.2-10 3.18.5-1ubuntu1.3 libedataserver-1.2-21 3.18.5-1ubuntu1.3 After a standard system update you need to restart your session to make all the necessary changes. References: https://usn.ubuntu.com/4429-1 CVE-2020-14928 Package Information: https://launchpad.net/ubuntu/+source/evolution-data-serve... https://launchpad.net/ubuntu/+source/evolution-data-serve... https://launchpad.net/ubuntu/+source/evolution-data-serve... -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds