Bug 14281 - claws-mail new security issue CVE-2014-2576
Summary: claws-mail new security issue CVE-2014-2576
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/616167/
Whiteboard: MGA4-64-OK MGA4-32-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-10-14 23:44 CEST by David Walser
Modified: 2014-11-14 12:50 CET (History)
5 users (show)

See Also:
Source RPM: claws-mail-3.9.3-1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-10-14 23:44:15 CEST
OpenSuSE has issued an advisory today (October 14):
http://lists.opensuse.org/opensuse-updates/2014-10/msg00015.html

The rssyl plugin doesn't support verifying TLS certificates.  This is fixed upstream in 3.10.1 (which we have in Cauldron).

It's a pretty minor issue, so I'll leave it to Jani to decide if we should update this for stable.

Mageia 3 is also affected.

Reproducible: 

Steps to Reproduce:
David Walser 2014-10-14 23:44:21 CEST

Whiteboard: (none) => MGA3TOO

Comment 1 Jani Välimaa 2014-10-31 16:31:13 CET
Pushed 3.11.1 to core/updates_testing for mga4. Please test.

Pkgs:
claws-mail-3.11.1-1.mga4
claws-mail-tools-3.11.1-1.mga4
claws-mail-devel-3.11.1-1.mga4
claws-mail-plugins-3.11.1-1.mga4
claws-mail-archive-plugin-3.11.1-1.mga4
claws-mail-bogofilter-plugin-3.11.1-1.mga4
claws-mail-gdata-plugin-3.11.1-1.mga4
claws-mail-smime-plugin-3.11.1-1.mga4
claws-mail-pgpcore-plugin-3.11.1-1.mga4
claws-mail-pgpinline-plugin-3.11.1-1.mga4
claws-mail-pgpmime-plugin-3.11.1-1.mga4
claws-mail-spamassassin-plugin-3.11.1-1.mga4
claws-mail-acpi-plugin-3.11.1-1.mga4
claws-mail-att_remover-plugin-3.11.1-1.mga4
claws-mail-bsfilter-plugin-3.11.1-1.mga4
claws-mail-fancy-plugin-3.11.1-1.mga4
claws-mail-fetchinfo-plugin-3.11.1-1.mga4
claws-mail-mailmbox-plugin-3.11.1-1.mga4
claws-mail-newmail-plugin-3.11.1-1.mga4
claws-mail-notification-plugin-3.11.1-1.mga4
claws-mail-perl-plugin-3.11.1-1.mga4
claws-mail-python-plugin-3.11.1-1.mga4
claws-mail-rssyl-plugin-3.11.1-1.mga4
claws-mail-vcalendar-plugin-3.11.1-1.mga4
claws-mail-vcalendar-plugin-devel-3.11.1-1.mga4
claws-mail-attachwarner-plugin-3.11.1-1.mga4
claws-mail-spam_report-plugin-3.11.1-1.mga4
claws-mail-tnef_parse-plugin-3.11.1-1.mga4
claws-mail-address_keeper-plugin-3.11.1-1.mga4
claws-mail-clamd-plugin-3.11.1-1.mga4
claws-mail-pdf_viewer-plugin-3.11.1-1.mga4
claws-mail-libravatar-plugin-3.11.1-1.mga4

P.S. I think I'm not going to touch mga3.

Assignee: jani.valimaa => qa-bugs

Comment 2 David Walser 2014-10-31 17:55:11 CET
Thanks Jani!

Dropping Mageia 3 from the whiteboard as the maintainer has no intention of updating it.

Advisory:
----------------------------------------

This update provides claws-mail version 3.11.1, which includes several fixes
and improvements related to SSL/TLS, and fixes other bugs as well.  See the
upstream news for more details.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2576
http://www.claws-mail.org/news.php
http://sourceforge.net/p/claws-mail/news/
http://lists.opensuse.org/opensuse-updates/2014-10/msg00015.html

Whiteboard: MGA3TOO => (none)

David Walser 2014-10-31 17:55:46 CET

CC: (none) => jani.valimaa

Comment 3 Otto Leipälä 2014-11-13 15:45:47 CET
Testing complete Mga4 64&32 validated update.
Sysadmins push this updates.

Keywords: (none) => validated_update
CC: (none) => ozkyster, sysadmin-bugs
Whiteboard: (none) => MGA4-64-OK MGA4-32-OK

Comment 4 Jani Välimaa 2014-11-13 15:59:29 CET
Maybe we should push new libetpan with claws-mail too? David, do you have any thoughts about it?
Comment 5 David Walser 2014-11-13 16:00:38 CET
I'm not all that concerned about POODLE issues, but I have no problem with updating libetpan if you want to or think it maybe should be.  I don't have strong feelings about it either way.
Comment 6 Jani Välimaa 2014-11-13 16:07:01 CET
OK, lets push claws-mail without touching libetpan. New libetpan would mean rebuilding claws-mail as lib major was bumped in libetpan 1.5.

I'll reconsider pushing libetpan if users reports issues with claws-mail.
Comment 7 David Walser 2014-11-14 04:42:01 CET
Was there an error that caused this to not be pushed?

CC: (none) => pterjan

Comment 8 Rémi Verschelde 2014-11-14 12:03:42 CET
No advisory on SVN :-) It's now uploaded.

CC: (none) => remi
Whiteboard: MGA4-64-OK MGA4-32-OK => MGA4-64-OK MGA4-32-OK advisory

Comment 9 Mageia Robot 2014-11-14 12:50:31 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2014-0449.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.