[CLSA-2025:1738170525] Fix CVE(s): CVE-2019-18928
Type:
security
Severity:
Critical
Release date:
2025-01-29 17:08:51 UTC
Description:
* SECURITY UPDATE: Privilege escalation via HTTP request interpretation - debian/patches/CVE-2019-18928.patch: drop auth credentials if not a backend in a Murder to prevent unauthorized access - CVE-2019-18928
Updated packages:
  • cyrus-admin_2.5.10-3ubuntu1.1+tuxcare.els2_all.deb
    sha:de98966922b06e8ae8ed7397e89ee05a7d091456
  • cyrus-caldav_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:d475a68b81bac9b6aba932226ab868322a9c47db
  • cyrus-clients_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:8be9adbc62e54ce211b15bdbe67d9db82a3ef778
  • cyrus-common_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:83f684bb66545f891b0785f768a70042e6804faa
  • cyrus-dev_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:e496c229122b4bb37c7012f813534ab1686b6c4a
  • cyrus-doc_2.5.10-3ubuntu1.1+tuxcare.els2_all.deb
    sha:ed29c7870bb01b65c27987bb2108da904507d14a
  • cyrus-imapd_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:7de0574a2fcc942a0e9262d6bcfb4b15ddf2a32a
  • cyrus-murder_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:8deeefc9bd22bebf13a4c2b3771f3140ed6f4ffb
  • cyrus-nntpd_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:ca0d88bb6aa1a80198f9f2579fc9a0297579eccc
  • cyrus-pop3d_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:7b8dd71255e911f9c7eb7ac90f2be04a6956bb88
  • cyrus-replication_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:4b1d47ec85e6e8ec55a717fa5be6428d83461282
  • libcyrus-imap-perl_2.5.10-3ubuntu1.1+tuxcare.els2_amd64.deb
    sha:e2ea9c353289d630657937210a0fcd5e32163261
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.