==========================================================================
Ubuntu Security Notice USN-4598-1
October 22, 2020
libetpan vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 16.04 LTS
Summary:
LibEtPan could be made to expose sensitive information over the network.
Software Description:
– libetpan: Mail Framework for C Language
Details:
It was discovered that LibEtPan incorrectly handled STARTTLS when using
IMAP, SMTP and POP3. A remote attacker could possibly use this issue
to perform a response injection attack. (CVE-2020-15953)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
libetpan-dev 1.6-1ubuntu0.1
libetpan17 1.6-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4598-1
CVE-2020-15953
Package Information:
https://launchpad.net/ubuntu/+source/libetpan/1.6-1ubuntu0.1
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEE7MowLJorxPNkyBZZW+PTAFZKyRgFAl+RlgkACgkQW+PTAFZK
yRjrWw/9HlZsxOLDK+BVPrVupw6meEFJ+jVWk9yQiX0QkIp4ARy2boNQP0PpZo8m
Nzpa8I90LzohVYoE8ted4r4rKHp0NG8vzDctWHGyGlnzW/ttEtbzhL4B2cQ1ITuw
XFi/jJCwGY5QdtaCCJ+mf0bgwcnf0YeskwiXKDcTW+nEMTzxUWe4NH6V0BDQFjqP
lwLgk7gE0QBLxufbbIlb/myZwMkkvTaXnbmGKe2ZGjJVwP4Dsn9TKs7FI7oOEA/N
+9nEQdyGae862npNyf1x4hbgBKqyjqpHmZuJ/P4yBldyZSY67l5/vgmi6lMoHXPD
9balUuvpXFha85e5YCN10gnn/6X1RsEtqo6P5zvR5Dx4BLwbC2gc6+5pKaVFzHzT
hbapO6oIsyNJpvODc1+HGG/fDaY/A8crkP/v1wGav+CsCY8PePYaLS1/Mz3nTxiw
aBsDbSXzMTHFAKQdDNsq6DCQUm5d6zIzoZtpa2fJwO+PVn1Yyc07SLSL4Nc6zroK
2T4z7WIC/yCKCwvmvWeoGZ8r3WiPZvG/jXAZRWwURJGcgqFgGwSnce26BXT5BK0A
qcpif8JZcY2FUBUEPhJJBiYBFOheiUAtY5+Sysa8P1M6UAUY92KxIhc2IZv2Lov1
JQdL6I7EIguP/51u4a1Dz+8KMn86XKss10Rt4jLBcKNcUfv5nS0=
=hGbU
—–END PGP SIGNATURE—–
—