SB2019021922 - Arch Linux update for msmtp



SB2019021922 - Arch Linux update for msmtp

Published: February 19, 2019

Security Bulletin ID SB2019021922
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2019-8337)

The vulnerability allows a remote authenticated attacker to bypass security restrictions on the system.

The vulnerability exists due to improper certificate verification when the affected software uses the new system default value for the  tls_trust_file command in its default configuration file. A remote attacker can send an email to an SMTP server and bypass certificate verification and conduct further attacks. 


Remediation

Install update from vendor's website.