Описание
Security update for cyrus-imapd
This update for cyrus-imapd fixes the following issues:
Changes in cyrus-imapd:
-
cyrus-imapd don't start because of missing "Requires=var-run.mount" from systemd (bsc#1251788) Remove var-run.mount from Requires and After
-
update to version 3.8.6 (bugfix release) VUL-0: CVE-2025-49812: cyrus-imapd: Opossum Attack Application Layer Desynchronization using Opportunistic TLS (bsc#1246165) The industry is deprecating STARTTLS (aka opportunistic TLS) in favor of implicit TLS over a dedicated port. STARTTLS is now disabled by default.
- Fixed issue #5477: master: tighten up pidfile/etc handling (bsc#1241543) VUL-0: cyrus-imapd: privilege drop happens too late, opening attack vectors from cyrus to root
- Fixed issue #5450: fix zoneinfo_db code for GCC 15 (thanks Yadd)
- Fixed issue #5309: deadlock on shutdown (thanks Mark Cammidge)
- Fixed issue #5424: recognise service-specific SASL options in
cyr_info conf-lint - Fixed issue #5420: fix double-free in http_admin (thanks Wolfgang Breyha)
- Fixed issue #5460: pop3d: add basic prometheus support (thanks Wolfgang Breyha)
- Fixed issue #5454: httpd fails to parse OpenSSL version for status string
-
update to version 3.8.5 (bugfix release)
- Fixed Issue #5029: check for unexpected extra tiny-tests directories
- Fixed Issue #5148: added --enable-release-checks configure option for use when building releases
- Fixed Issue #4489: calendar-color "changes" namespace (thanks Дилян Палаузов)
- Fixed Issue #5009: various portability warnings and nits
- Fixed Issue #5050: iTIP line endings (thanks Дилян Палаузов)
- Fixed Issue #5052: iMIP line endings (thanks Дилян Палаузов)
- Fixed Issue #5072: http_cgi use after free (thanks Дилян Палаузов)
- Fixed Issue #5094: httpd crash when PROPFIND url is /dav/calendars
- Fixed Issue #5118: broken language checks for "zr-hant" and "sr-me"
- Fixed Issue #5047: proxying UID SEARCH
-
CVE-2025-23394: cyrus-imapd: daily-backup.sh allows escalation from cyrus to root (bsc#1241536)
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1241536
- SUSE Bug 1241543
- SUSE Bug 1246165
- SUSE Bug 1251788
- SUSE CVE CVE-2025-23394 page
- SUSE CVE CVE-2025-49812 page
Описание
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.
Затронутые продукты
Ссылки
- CVE-2025-23394
- SUSE Bug 1241536
Описание
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
Затронутые продукты
Ссылки
- CVE-2025-49812
- SUSE Bug 1246161
- SUSE Bug 1261312