Oval Definition:oval:com.redhat.rhsa:def:20110859
Revision Date:2011-06-08Version:643
Title:RHSA-2011:0859: cyrus-imapd security update (Moderate)
Description:The cyrus-imapd packages contain a high-performance mail server with IMAP, POP3, NNTP, and Sieve support.

  • It was discovered that cyrus-imapd did not flush the received commands buffer after switching to TLS encryption for IMAP, LMTP, NNTP, and POP3 sessions. A man-in-the-middle attacker could use this flaw to inject protocol commands into a victim's TLS session initialization messages. This could lead to those commands being processed by cyrus-imapd, potentially allowing the attacker to steal the victim's mail or authentication credentials. (CVE-2011-1926)

    Users of cyrus-imapd are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the update, cyrus-imapd will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-1926
    CVE-2011-1926
    RHSA-2011:0859
    RHSA-2011:0859-01
    RHSA-2011:0859-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-devel is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-murder is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-murder is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-nntp is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-nntp is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • perl-Cyrus is earlier than 0:2.2.12-15.el4
  • AND perl-Cyrus is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.3.7-7.el5_6.4
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_6.4
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_6.4
  • AND cyrus-imapd-perl is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_6.4
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • cyrus-imapd is earlier than 0:2.3.16-6.el6_1.2
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.2
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.2
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • cyrus-imapd-devel is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-devel is signed with Red Hat master key
  • cyrus-imapd-nntp is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-nntp is signed with Red Hat master key
  • cyrus-imapd-utils is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-utils is signed with Red Hat master key
  • cyrus-imapd is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd is signed with Red Hat master key
  • perl-Cyrus is earlier than 0:2.2.12-15.el4
  • AND perl-Cyrus is signed with Red Hat master key
  • cyrus-imapd-murder is earlier than 0:2.2.12-15.el4
  • AND cyrus-imapd-murder is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 6 Client is installed
  • OR Red Hat Enterprise Linux 6 Server is installed
  • OR Red Hat Enterprise Linux 6 Workstation is installed
  • OR Red Hat Enterprise Linux 6 ComputeNode is installed
  • AND
  • cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.2
  • AND cyrus-imapd-devel is signed with Red Hat redhatrelease2 key
  • cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.2
  • AND cyrus-imapd-utils is signed with Red Hat redhatrelease2 key
  • cyrus-imapd is earlier than 0:2.3.16-6.el6_1.2
  • AND cyrus-imapd is signed with Red Hat redhatrelease2 key
  • BACK