=========================================================================Ubuntu Security Notice USN-1295-1
December 08, 2011

dovecot vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10

Summary:

Dovecot could be made to expose sensitive information over the network.

Software Description:
- dovecot: IMAP and POP3 email server

Details:

It was discovered that Dovecot incorrectly validated certificate hostnames
when being used as a POP3 and IMAP proxy. If a remote attacker were able to
perform a man-in-the-middle attack, this flaw could be exploited to view
sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  dovecot-common                  1:2.0.13-1ubuntu3.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-1295-1
  CVE-2011-4318

Package Information:
  https://launchpad.net/ubuntu/+source/dovecot/1:2.0.13-1ubuntu3.2


Ubuntu 1295-1: Dovecot vulnerability

December 8, 2011
Dovecot could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: dovecot-common 1:2.0.13-1ubuntu3.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1295-1

CVE-2011-4318

Severity
December 08, 2011

Package Information

https://launchpad.net/ubuntu/+source/dovecot/1:2.0.13-1ubuntu3.2

Related News