From 3cf7c3ef441822c889356fd1812ebf2944a59851 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 25 Aug 2020 10:45:55 +0100 Subject: gentoo resync : 25.08.2020 --- metadata/glsa/glsa-202007-55.xml | 50 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 metadata/glsa/glsa-202007-55.xml (limited to 'metadata/glsa/glsa-202007-55.xml') diff --git a/metadata/glsa/glsa-202007-55.xml b/metadata/glsa/glsa-202007-55.xml new file mode 100644 index 000000000000..cb2f337bffdb --- /dev/null +++ b/metadata/glsa/glsa-202007-55.xml @@ -0,0 +1,50 @@ + + + + libetpan: Improper STARTTLS handling + A vulnerability was discovered in libetpan's STARTTLS handling, + possibly allowing an integrity/confidentiality compromise. + + libetpan + 2020-07-28 + 2020-07-28 + 734130 + remote + + + 1.9.4-r1 + 1.9.4-r1 + + + +

libetpan is a portable, efficient middleware for different kinds of mail + access. +

+
+ +

It was discovered that libetpan was not properly handling state within + the STARTTLS protocol handshake. +

+
+ +

There may be a breach of integrity or confidentiality in connections + made using libetpan with STARTTLS. +

+
+ +

There is no known workaround at this time.

+
+ +

All libetpan users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-libs/libetpan-1.9.4-r1" + +
+ + CVE-2020-15953 + + sam_c + sam_c +
-- cgit v1.2.3