[CLSA-2023:1688678110] Fix CVE(s): CVE-2021-33582
Type:
security
Severity:
Important
Release date:
2023-07-06 21:15:14 UTC
Description:
* SECURITY UPDATE: String hashing algorithm collisions - debian/patches/0021-CVE-2021-33582-pre.patch: gracefully handle lookup on zero-sized tables - debian/patches/0022-CVE-2021-33582.patch: replace ad-hoc algorithm with seeded djb2 and use it when hashing - CVE-2021-33582 * Enable the internal cunit tests * CUnit tests: - debian/patches/0023-Add-unit-tests-for-strhash.patch: add unit tests for strhash and hash quality - debian/patches/0024-Skip-several-failed-tests.patch: skip several failed tests
Updated packages:
  • cyrus-admin_2.5.10-3ubuntu1.1+tuxcare.els1_all.deb
    sha:07f07b7f604a8d8bcc5695938cca4b5af8a56921
  • cyrus-caldav_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:6e0cabd71bd26bb3135f23d39187dddc587a6967
  • cyrus-clients_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:f345bf2615b31b1746606cb9cdd4656d6036aa77
  • cyrus-common_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:c3738a77ad9ecf88070c99c83e338a3c3e844785
  • cyrus-dev_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:44db7b20d203820a10836fbe27f998110754cbd5
  • cyrus-doc_2.5.10-3ubuntu1.1+tuxcare.els1_all.deb
    sha:34c7c2d4c32c95c41e7df41641148dd2de9f957d
  • cyrus-imapd_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:679ee5e5efa4b2be3fd43584f2a0a324655b902b
  • cyrus-murder_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:bf133f9a007913f1e130c901e7e5982fc1a57062
  • cyrus-nntpd_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:7bf55b417fb361400b2a8a3a49e8bbdcc91fc4d1
  • cyrus-pop3d_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:39149e62ae3312b2a2ab4deea23ce6369cac083e
  • cyrus-replication_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:c36b22f7f7610cf5df946f80db313ae4e10b4aa4
  • libcyrus-imap-perl_2.5.10-3ubuntu1.1+tuxcare.els1_amd64.deb
    sha:6d02616419321b9895f1863c07068396eaf91970
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.