-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2021-b7fdb7e69a 2021-12-13 01:03:28.685507 --------------------------------------------------------------------------------
Name : isync Product : Fedora 35 Version : 1.4.4 Release : 1.fc35 URL : http://isync.sourceforge.net/ Summary : Tool to synchronize IMAP4 and Maildir mailboxes Description : mbsync is a command line application which synchronizes mailboxes. Currently Maildir and IMAP4 mailboxes are supported. New messages, message deletions and flag changes can be propagated both ways. mbsync is suitable for use in IMAP-disconnected mode.
-------------------------------------------------------------------------------- Update Information:
Update to fix CVE-2021-44143 and CVE-2021-3657 -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 3 2021 Dan ��erm��k dan.cermak@cgc-instruments.com - 1.4.4-1 - New upstream release 1.4.4 - Fixes rhbz#2028810 - Fixes CVE-2021-3657 - Fixes CVE-2021-44143 * Tue Sep 14 2021 Sahana Prasad sahana@redhat.com - 1.4.3-2 - Rebuilt with OpenSSL 3.0.0 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2027173 - CVE-2021-44143 isync: specially crafted mail message may cause heap overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2027173 [ 2 ] Bug #2028933 - CVE-2021-3657 isync: buffer overflows due to inadequate handling of extremely large IMAP literals [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2028933 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-b7fdb7e69a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org