First published: Mon Oct 21 2019(Updated: )
It was discovered that UW IMAP incorrectly handled inputs. A remote attacker could possibly use this issue to execute arbitrary OS commands.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libc-client2007e | <8:2007f~dfsg-5ubuntu0.19.04.2 | 8:2007f~dfsg-5ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/mlock | <8:2007f~dfsg-5ubuntu0.19.04.2 | 8:2007f~dfsg-5ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/uw-mailutils | <8:2007f~dfsg-5ubuntu0.19.04.2 | 8:2007f~dfsg-5ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/libc-client2007e | <8:2007f~dfsg-5ubuntu0.18.04.2 | 8:2007f~dfsg-5ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/mlock | <8:2007f~dfsg-5ubuntu0.18.04.2 | 8:2007f~dfsg-5ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/uw-mailutils | <8:2007f~dfsg-5ubuntu0.18.04.2 | 8:2007f~dfsg-5ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libc-client2007e | <8:2007f~dfsg-4+deb8u1build0.16.04.1 | 8:2007f~dfsg-4+deb8u1build0.16.04.1 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/mlock | <8:2007f~dfsg-4+deb8u1build0.16.04.1 | 8:2007f~dfsg-4+deb8u1build0.16.04.1 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/uw-mailutils | <8:2007f~dfsg-4+deb8u1build0.16.04.1 | 8:2007f~dfsg-4+deb8u1build0.16.04.1 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4160-1 is considered a high-severity vulnerability due to its potential for remote code execution.
To fix USN-4160-1, you should update the affected packages including libc-client2007e, mlock, and uw-mailutils to the latest version provided for your Ubuntu release.
USN-4160-1 affects Ubuntu versions 16.04, 18.04, and 19.04.
Due to USN-4160-1, a remote attacker could potentially execute arbitrary OS commands on the affected systems.
Yes, USN-4160-1 is primarily related to the UW IMAP package and its handling of user inputs.