Bug 27035 - kdepim-runtime, kmail-account-wizard new security issue CVE-2020-15954
Summary: kdepim-runtime, kmail-account-wizard new security issue CVE-2020-15954
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-08-04 23:57 CEST by David Walser
Modified: 2020-08-25 10:14 CEST (History)
4 users (show)

See Also:
Source RPM: kdepim-runtime-20.04.3-1.mga8.src.rpm, kmail-account-wizard-20.04.3-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-08-04 23:57:00 CEST
Debian-LTS has issued an advisory on July 30:
https://www.debian.org/lts/security/2020/dla-2300

Mageia 7 is also affected.
David Walser 2020-08-04 23:57:07 CEST

Whiteboard: (none) => MGA7TOO

Comment 1 David GEIGER 2020-08-06 09:58:31 CEST
Done for both Cauldron and mga7!

CC: (none) => geiger.david68210

Comment 2 David Walser 2020-08-06 20:58:28 CEST
Advisory:
========================

Updated kdepim-runtime and kmail-account-wizard packages fix security
vulnerability:

It was discovered that there was an issue where kmail would default to using
unencrypted POP3 communication despite the UI indicating that encryption was in
use (CVE-2020-15954).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15954
https://www.debian.org/lts/security/2020/dla-2300
========================

Updated packages in core/updates_testing:
========================
kmail-account-wizard-19.04.0-1.1.mga7
akonadi-kde-19.04.0-1.2.mga7
libakonadi-singlefileresource5-19.04.0-1.2.mga7
libmaildir5-19.04.0-1.2.mga7
libakonadi-filestore5-19.04.0-1.2.mga7
libkmindexreader5-19.04.0-1.2.mga7
libfolderarchivesettings5-19.04.0-1.2.mga7
kdepim-runtime-handbook-19.04.0-1.2.mga7

from SRPMS:
kmail-account-wizard-19.04.0-1.1.mga7.src.rpm
kdepim-runtime-19.04.0-1.2.mga7.src.rpm

Version: Cauldron => 7
Whiteboard: MGA7TOO => (none)
Assignee: kde => qa-bugs

Comment 3 Herman Viaene 2020-08-10 11:16:42 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
No previous updates, so tried my luck at using commands.
Used accountwizard command to define what???-kmail??? my hotmail account, choosing pop3.
After completing that, lauched kmail, but could not read the e-mail account, it is there but only half way e.g. it does not show up in the folders or in the sequence list of accounts Ouutgoing account is completely absent
Giving up on this

CC: (none) => herman.viaene

Comment 4 Ulrich Beckmann 2020-08-22 17:15:11 CEST
Kmail-account-wizard is a graphical interface, which is started when you invoke kmail the first time. 

As a KMail user, I think it never led to complete configs, but you have to go through the KMail configuration afterwards. It is meant to facilitate configuration. Will try it in a new user.

CC: (none) => bequimao.de

Comment 5 Ulrich Beckmann 2020-08-24 21:17:23 CEST
Installed Packages
akonadi-kde.x86_64                                                                    2:19.04.0-1.2.mga7                                                @updates_testing-x86_64
kmail-account-wizard.x86_64                                                           2:19.04.0-1.1.mga7                                                @updates_testing-x86_64
lib64akonadi-filestore5.x86_64                                                        2:19.04.0-1.2.mga7                                                @updates_testing-x86_64
lib64akonadi-singlefileresource5.x86_64                                               2:19.04.0-1.2.mga7                                                @updates_testing-x86_64
lib64folderarchivesettings5.x86_64                                                    2:19.04.0-1.2.mga7                                                @updates_testing-x86_64
lib64kmindexreader5.x86_64                                                            2:19.04.0-1.2.mga7                                                @updates_testing-x86_64
lib64maildir5.x86_64                                                                  2:19.04.0-1.2.mga7                                                @updates_testing-x86_64
Available Packages
kdepim-runtime-handbook.noarch                                                        2:19.04.0-1.2.mga7                                                updates_testing-x86_64 


I tested now with new user and a GMail IMAP account.
It created an empty default identity named unnamed, though I had given my real name.
Receiving account had the login name as user name, and no IMAP server, perhaps because of the ending ...@googlemail.com instead of gmail.com.
Sending account working. Sent a test mail sucessfully.

Though config is incomplete, it is helpful as it normally gives server names and ports. Other mail programs may be better, but I see no regression. I would give it a Go.

Ulrich
Comment 6 David Walser 2020-08-25 00:06:49 CEST
Advisory and package list in Comment 2.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA7-64-OK
CC: (none) => sysadmin-bugs

Aurelien Oudelet 2020-08-25 00:17:04 CEST

Keywords: (none) => advisory

Comment 7 Mageia Robot 2020-08-25 10:14:48 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0346.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.