First published: Tue May 28 2024(Updated: )
It was discovered that amavisd-new incorrectly handled certain MIME email messages with multiple boundary parameters. A remote attacker could possibly use this issue to bypass checks for banned files or malware.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/amavisd-new | <1:2.13.0-3ubuntu2 | 1:2.13.0-3ubuntu2 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/amavisd-new | <1:2.13.0-3ubuntu1.1 | 1:2.13.0-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/amavisd-new | <1:2.12.2-1ubuntu1.1 | 1:2.12.2-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/amavisd-new | <1:2.11.0-6.1ubuntu1.1 | 1:2.11.0-6.1ubuntu1.1 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-6790-1 is considered medium as it allows a remote attacker to potentially bypass checks for banned files or malware.
To fix USN-6790-1, update the amavisd-new package to the latest version specified for your Ubuntu release.
USN-6790-1 affects amavisd-new versions prior to 1:2.13.0-3ubuntu2 for Ubuntu 24.04, 1:2.13.0-3ubuntu1.1 for 23.10, 1:2.12.2-1ubuntu1.1 for 22.04, and 1:2.11.0-6.1ubuntu1.1 for 20.04.
Users of amavisd-new on supported versions of Ubuntu that are running affected versions are impacted by this vulnerability.
USN-6790-1 is a security vulnerability related to improper handling of certain MIME email messages by amavisd-new.