| Summary: | apache-commons-email new security issue CVE-2018-1294 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | davidwhodgins, geiger.david68210, herman.viaene, sysadmin-bugs |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-32-OK | ||
| Source RPM: | apache-commons-email-1.3.1-11.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-01-27 12:01:43 CET
David Walser
2018-01-27 12:02:07 CET
Whiteboard:
(none) =>
MGA6TOO
David Walser
2018-02-02 18:32:25 CET
Status comment:
(none) =>
Fixed upstream in 1.5 openSUSE has issued an advisory for this on February 6: https://lists.opensuse.org/opensuse-updates/2018-02/msg00015.html Fedora has issued an advisory for this on February 14: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6BK3RDWBGNZHZ6LDJ34DAWVCBE2UGUE3/ Done for Cauldron and also for mga6! CC:
(none) =>
geiger.david68210 Thanks David! Advisory: ======================== Updated apache-commons-email packages fix security vulnerability: Apache Commons-Email, from version 1.0 to 1.4 inclusive, does not properly validate bounce addresses. If a user of Commons-Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated (CVE-2018-1294). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1294 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6BK3RDWBGNZHZ6LDJ34DAWVCBE2UGUE3/ ======================== Updated packages in core/updates_testing: ======================== apache-commons-email-1.5-1.mga6 apache-commons-email-javadoc-1.5-1.mga6 from apache-commons-email-1.5-1.mga6.src.rpm Whiteboard:
MGA6TOO =>
(none) MGA6-32 on Dell Latitude D600 Mate No installation issues. Ref to bug 21435 OK'ing on clean install. Checked at least thunderbird is not disturbed. OK. CC:
(none) =>
herman.viaene Advisory committed to svn. Validating based on above test. Keywords:
(none) =>
advisory, validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0136.html Resolution:
(none) =>
FIXED |