UbuntuUpdates.org

Package "uw-imap"

Name: uw-imap

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • c-client library for mail protocols - library files
  • c-client library for mail protocols - development files
  • mailbox locking program
  • c-client support programs

Latest version: 8:2007f~dfsg-5ubuntu0.18.04.2
Release: bionic (18.04)
Level: updates
Repository: universe

Links



Other versions of "uw-imap" in Bionic

Repository Area Version
base universe 8:2007f~dfsg-5build1
security universe 8:2007f~dfsg-5ubuntu0.18.04.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8:2007f~dfsg-5ubuntu0.18.04.2 2019-10-21 21:07:35 UTC

  uw-imap (8:2007f~dfsg-5ubuntu0.18.04.2) bionic-security; urgency=medium

  * SECURITY UPDATE: Argument injection.
    - debian/patches/2013_disable_rsh.patch: Disable access to IMAP mailboxes
      through running imapd over rsh, and therefore ssh. Code using the library
      can enable it with tcp_parameters() after making sure that the IMAP
      server name is sanitized.
    - CVE-2018-19518

 -- Eduardo Barretto <email address hidden> Thu, 17 Oct 2019 10:52:18 -0300

Source diff to previous version
CVE-2018-19518 University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_

Version: 8:2007f~dfsg-5ubuntu0.18.04.1 2019-08-29 10:07:04 UTC

  uw-imap (8:2007f~dfsg-5ubuntu0.18.04.1) bionic; urgency=medium

  * 2014_openssl1.1.1_sni.patch (new): Use SNI when building
    with OpenSSL 1.1.1 / TLSv1.3 support, since some servers
    (e.g., imap.gmail.com, imap.mail.att.net) require SNI on
    TLSv1.3 to pass certificate verification. (LP: #1834340)
  * debian/control.in.in: Update maintainer that lasts build.

 -- Mauricio Faria de Oliveira <email address hidden> Fri, 09 Aug 2019 11:51:00 -0300




About   -   Send Feedback to @ubuntu_updates