Bug 47542 - evolution-data-server: Multiple issues (4.2)
evolution-data-server: Multiple issues (4.2)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.2
All Linux
: P3 normal (vote)
: UCS 4.2-4-errata
Assigned To: Quality Assurance
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-08-09 10:19 CEST by Quality Assurance
Modified: 2018-08-15 16:20 CEST (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 5.3 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2018-08-09 10:19:21 CEST
New Debian evolution-data-server 3.12.9~git20141128.5242b0-2+deb8u4 fixes:
This update addresses the following issue(s):
* 
* camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly. (CVE-2016-10727)
CVE_2018-12422 is open

3.12.9~git20141128.5242b0-2+deb8u4 (Wed, 25 Jul 2018 12:06:29 +0800) * CVE-2016-10727: Prevent an issue where "STARTTLS not supported" errors from IMAP servers were ignored leading to the use of insecure connections without the user's knowledge or consent.
* CVE-2016-10727 evolution-data-server: IMAPx Component Information Disclosure (CVE-2016-10727)
Comment 1 Quality Assurance univentionstaff 2018-08-09 18:48:14 CEST
--- mirror/ftp/4.2/unmaintained/4.2-0/source/evolution-data-server_3.12.9~git20141128.5242b0-2+deb8u3.dsc
+++ apt/ucs_4.2-0-errata4.2-4/source/evolution-data-server_3.12.9~git20141128.5242b0-2+deb8u4.dsc
@@ -1,3 +1,9 @@
+3.12.9~git20141128.5242b0-2+deb8u4 [Wed, 25 Jul 2018 12:06:29 +0800] Chris Lamb <lamby@debian.org>:
+
+  * CVE-2016-10727: Prevent an issue where "STARTTLS not supported" errors from
+    IMAP servers were ignored leading to the use of insecure connections
+    without the user's knowledge or consent.
+
 3.12.9~git20141128.5242b0-2+deb8u3 [Wed, 21 Dec 2016 18:31:01 +0100] Wouter Verhelst <wouter@debian.org>:
 
   * Non-maintainer upload.

<http://10.200.17.11/4.2-4/#4394725897985531557>
Comment 2 Philipp Hahn univentionstaff 2018-08-10 11:49:59 CEST
OK: yaml
OK: errata-announce
OK: patch
OK: piuparts

[4.2-4] e5bbba52f3 Bug #47542: evolution-data-server 3.12.9~git20141128.5242b0-2+deb8u4
 doc/errata/staging/evolution-data-server.yaml | 9 ++-------
 1 file changed, 2 insertions(+), 7 deletions(-)

[4.2-4] c94bef1b87 Bug #47542: evolution-data-server 3.12.9~git20141128.5242b0-2+deb8u4
 doc/errata/staging/evolution-data-server.yaml | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)
Comment 3 Arvid Requate univentionstaff 2018-08-15 16:20:30 CEST
<http://errata.software-univention.de/ucs/4.2/446.html>