SB2019021922 - Arch Linux update for msmtp
Published: February 19, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2019-8337)
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the system.
The vulnerability exists due to improper certificate verification when the affected software uses the new system default value for the tls_trust_file command in its default configuration file. A remote attacker can send an email to an SMTP server and bypass certificate verification and conduct further attacks.
Remediation
Install update from vendor's website.