USN-6790-1: amavisd-new vulnerability
It was discovered that amavisd-new incorrectly handled certain MIME email messages with multiple boundary parameters. A remote attacker could possibly use this issue to bypass checks for banned files or malware.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6790-1?
The severity of USN-6790-1 is considered medium as it allows a remote attacker to potentially bypass checks for banned files or malware.
How do I fix USN-6790-1?
To fix USN-6790-1, update the amavisd-new package to the latest version specified for your Ubuntu release.
What versions of amavisd-new are affected by USN-6790-1?
USN-6790-1 affects amavisd-new versions prior to 1:2.13.0-3ubuntu2 for Ubuntu 24.04, 1:2.13.0-3ubuntu1.1 for 23.10, 1:2.12.2-1ubuntu1.1 for 22.04, and 1:2.11.0-6.1ubuntu1.1 for 20.04.
Who is impacted by the vulnerability described in USN-6790-1?
Users of amavisd-new on supported versions of Ubuntu that are running affected versions are impacted by this vulnerability.
What type of vulnerability is USN-6790-1?
USN-6790-1 is a security vulnerability related to improper handling of certain MIME email messages by amavisd-new.