[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2281-1] evolution-data-server security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2281-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/               Emilio Pozuelo Monfort
July 16, 2020                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : evolution-data-server
Version        : 3.22.7-1+deb9u1
CVE ID         : CVE-2020-14928

Damian Poddebniak and Fabian Ising discovered a response injection
vulnerability in Evolution data server, which could enable MITM
attacks.

For Debian 9 stretch, this problem has been fixed in version
3.22.7-1+deb9u1.

We recommend that you upgrade your evolution-data-server packages.

For the detailed security status of evolution-data-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/evolution-data-server

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl8QGqgACgkQnUbEiOQ2
gwJoWA//bs5I4zDbO5IsBH2kCLnwLAQsLg/4pIEnDmHsHEP8VbKsh29UBm17VaN+
7k/OzY65+zW+V0mO7FNEq4leYKHAKDK/V+9R9RZAK6Dh5DfuVVhbcue8TLCAqu5F
opsbM0wmeMbzc2NvR8bcU9Fo2Jl+KEXxXi05nBeu38tXOgyA06CuDoar/bEfi4NE
gCTPUcdn82YMDcgunJ36Tg0uJ8/jsCuvd3rqxTd9ZoV3PisiJomqfIgZEEMzGeVK
79UcdbQBHfaycksh1SKabyDPU0YlR7Wtn2jsmzBjX2J24APdoyrdURikJHiu2f3s
5pTiMJ5vJK5UQSNT1WWwfI8OTYbdTFjPOUlziRoRALUsq2IarenkyWJnoxnIpfYv
xBFZklhtIvHOz97W9YCqCLM+Gebyr2UkFcDdEMBQEZMRHQESkj58UhW/GuekqCTi
J8VIH2xad6TeVWsDk/Y8cge+JooHL5MrUpR/tBNAhAFWVWK8qe+gC2g3/S5SlPSz
XDB6x3QhMJ1Chjpk+PBHOBkNKBZ+HAVfWb5P735c57gpTteUU1ikamBaWHNma9Sq
TYTKCWoM9OtLneUZZzPf1IL5N+xT4dAwzRkDBfatVZG0QAlSMwG/0mbBiZO6yz+p
iYhTI8jkSfqDQi0jiwO//1A8tGRf1jXj/F6jNtDgFpk4oHbaAmI=
=qyrw
-----END PGP SIGNATURE-----


Reply to: