Oval Definition:oval:com.redhat.rhsa:def:20091116
Revision Date:2009-06-18Version:645
Title:RHSA-2009:1116: cyrus-imapd security update (Important)
Description:The cyrus-imapd packages contain a high-performance mail server with IMAP, POP3, NNTP, and SIEVE support.

  • It was discovered that the Cyrus SASL library (cyrus-sasl) does not always reliably terminate output from the sasl_encode64() function used by programs using this library. The Cyrus IMAP server (cyrus-imapd) relied on this function's output being properly terminated. Under certain conditions, improperly terminated output from sasl_encode64() could, potentially, cause cyrus-imapd to crash, disclose portions of its memory, or lead to SASL authentication failures. (CVE-2009-0688)

    Users of cyrus-imapd are advised to upgrade to these updated packages, which resolve this issue. After installing the update, cyrus-imapd will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0688
    RHSA-2009:1116
    RHSA-2009:1116-01
    RHSA-2009:1116-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.2.12-10.el4_8.1
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.1
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.1
  • AND cyrus-imapd-murder is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.1
  • AND cyrus-imapd-nntp is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.1
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • perl-Cyrus is earlier than 0:2.2.12-10.el4_8.1
  • AND perl-Cyrus is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.3.7-2.el5_3.2
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-devel is earlier than 0:2.3.7-2.el5_3.2
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-perl is earlier than 0:2.3.7-2.el5_3.2
  • AND cyrus-imapd-perl is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.3.7-2.el5_3.2
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • BACK