You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa claws-mail

Sigurnosni nedostatak programskog paketa claws-mail

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2020-90e2b01f4a
2020-10-15 14:42:31.614647
——————————————————————————–

Name : claws-mail
Product : Fedora 31
Version : 3.17.7
Release : 1.fc31
URL : https://protect2.fireeye.com/v1/url?k=a4f7d908-f8e56d0c-a4f044c4-000babd90757-1988cb5a0003a88a&q=1&e=40d59f85-cc86-4cd7-a4e0-30b5eb808d14&u=http%3A%2F%2Fclaws-mail.org%2F
Summary : Email client and news reader based on GTK+
Description :
Claws Mail is an email client (and news reader), based on GTK+, featuring
quick response, graceful and sophisticated interface, easy configuration,
intuitive operation, abundant features, and extensibility.

——————————————————————————–
Update Information:

Update to 3.17.7 — https://protect2.fireeye.com/v1/url?k=88c2a3d6-d4d017d2-88c53e1a-000babd90757-e8706b17102fdb57&q=1&e=40d59f85-cc86-4cd7-a4e0-30b5eb808d14&u=https%3A%2F%2Fwww.claws-mail.org%2Fnews.php
——————————————————————————–
ChangeLog:

* Mon Sep 28 2020 Michael Schwendt <mschwendt@fedoraproject.org> – 3.17.7-1
– Update to 3.17.7. Also for CVE-2020-16094.
* Mon Jul 27 2020 Fedora Release Engineering <releng@fedoraproject.org> – 3.17.6-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1861975 – CVE-2020-16094 claws-mail: malicious IMAP server can trigger stack consumption
https://bugzilla.redhat.com/show_bug.cgi?id=1861975
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2020-90e2b01f4a’ at the command
line. For more information, refer to the dnf documentation available at
https://protect2.fireeye.com/v1/url?k=fcb4ac28-a0a6182c-fcb331e4-000babd90757-88ce41c1ad86db8b&q=1&e=40d59f85-cc86-4cd7-a4e0-30b5eb808d14&u=http%3A%2F%2Fdnf.readthedocs.io%2Fen%2Flatest%2Fcommand_ref.html%23upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2020-67d9661fe2
2020-10-15 14:27:18.899062
——————————————————————————–

Name : claws-mail
Product : Fedora 32
Version : 3.17.7
Release : 1.fc32
URL : https://protect2.fireeye.com/v1/url?k=237db1f9-7f6f05fd-237a2c35-000babd90757-436b5a14470baf85&q=1&e=4a1d5728-5d96-4a1d-84de-95024cda2921&u=http%3A%2F%2Fclaws-mail.org%2F
Summary : Email client and news reader based on GTK+
Description :
Claws Mail is an email client (and news reader), based on GTK+, featuring
quick response, graceful and sophisticated interface, easy configuration,
intuitive operation, abundant features, and extensibility.

——————————————————————————–
Update Information:

Update to 3.17.7 — https://protect2.fireeye.com/v1/url?k=f8b54439-a4a7f03d-f8b2d9f5-000babd90757-73e38d2a6dc69dd3&q=1&e=4a1d5728-5d96-4a1d-84de-95024cda2921&u=https%3A%2F%2Fwww.claws-mail.org%2Fnews.php
——————————————————————————–
ChangeLog:

* Mon Sep 28 2020 Michael Schwendt <mschwendt@fedoraproject.org> – 3.17.7-1
– Update to 3.17.7. Also for CVE-2020-16094.
* Mon Jul 27 2020 Fedora Release Engineering <releng@fedoraproject.org> – 3.17.6-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1861975 – CVE-2020-16094 claws-mail: malicious IMAP server can trigger stack consumption
https://bugzilla.redhat.com/show_bug.cgi?id=1861975
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2020-67d9661fe2’ at the command
line. For more information, refer to the dnf documentation available at
https://protect2.fireeye.com/v1/url?k=b258196b-ee4aad6f-b25f84a7-000babd90757-59247a8bf281fda4&q=1&e=4a1d5728-5d96-4a1d-84de-95024cda2921&u=http%3A%2F%2Fdnf.readthedocs.io%2Fen%2Flatest%2Fcommand_ref.html%23upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

AutorBruno Varga
Cert idNCERT-REF-2020-10-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa httpcomponents

Otkriven je sigurnosni nedostatak u programskom paketu httpcomponents za operacijski sustav Debian. Otkriveni nedostatak potencijalnim napadačima omogućuje zaobilaženje sigurnosnih ograničenja....

Close