USN-4429-1: Evolution Data Server vulnerability
Published Jul 22, 2020
·Updated
It was discovered that Evolution Data Server incorrectly handled STARTTLS when using SMTP and POP3. A remote attacker could possibly use this issue to perform a response injection attack.
Affected Software
30 affected componentsFixes available
All of the following
ubuntu/evolution-data-server<3.36.3-0ubuntu1.1
3.36.3-0ubuntu1.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/evolution-data-server-common<3.36.3-0ubuntu1.1
3.36.3-0ubuntu1.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libcamel-1.2-62<3.36.3-0ubuntu1.1
3.36.3-0ubuntu1.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libebackend-1.2-10<3.36.3-0ubuntu1.1
3.36.3-0ubuntu1.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libedataserver-1.2-24<3.36.3-0ubuntu1.1
3.36.3-0ubuntu1.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/evolution-data-server<3.28.5-0ubuntu0.18.04.3
3.28.5-0ubuntu0.18.04.3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/evolution-data-server-common<3.28.5-0ubuntu0.18.04.3
3.28.5-0ubuntu0.18.04.3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libcamel-1.2-61<3.28.5-0ubuntu0.18.04.3
3.28.5-0ubuntu0.18.04.3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libebackend-1.2-10<3.28.5-0ubuntu0.18.04.3
3.28.5-0ubuntu0.18.04.3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libedataserver-1.2-23<3.28.5-0ubuntu0.18.04.3
3.28.5-0ubuntu0.18.04.3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/evolution-data-server<3.18.5-1ubuntu1.3
3.18.5-1ubuntu1.3
Ubuntu Ubuntu=16.04
All of the following
ubuntu/evolution-data-server-common<3.18.5-1ubuntu1.3
3.18.5-1ubuntu1.3
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libcamel-1.2-54<3.18.5-1ubuntu1.3
3.18.5-1ubuntu1.3
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libebackend-1.2-10<3.18.5-1ubuntu1.3
3.18.5-1ubuntu1.3
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libedataserver-1.2-21<3.18.5-1ubuntu1.3
3.18.5-1ubuntu1.3
Ubuntu Ubuntu=16.04
Event History
Jul 22, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID?
USN-4429-1
2
What software is affected by this vulnerability?
Evolution Data Server
3
How does the vulnerability occur?
Evolution Data Server incorrectly handles STARTTLS when using SMTP and POP3.
4
What is the potential impact of this vulnerability?
A remote attacker could use this vulnerability to perform a response injection attack.
5
How do I fix this vulnerability?
Install the latest version of Evolution Data Server.