Security update for cyrus-imapd

Announcement ID: SUSE-SU-2016:1459-1
Rating: important
References:
Cross-References:
CVSS scores:
  • CVE-2014-3566 ( NVD ): 3.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Affected Products:
  • SLES for SAP Applications 11-SP4
  • SUSE Linux Enterprise Server 11 SP4
  • SUSE Linux Enterprise Software Development Kit 11 SP4

An update that solves four vulnerabilities and has one security fix can now be installed.

Description:

This update for cyrus-imapd fixes the following issues:

  • Previous versions of cyrus-imapd would not allow its users to disable old SSL variants that are vulnerable to attacks like BEAST and POODLE. This patch adds the configuration option 'tls_versions' to remedy that issue. Note that users who upgrade an existing installation will not have their imapd.conf file overwritten, i.e. their IMAP server will continue to support SSLv2 and SSLv3 like before. To disable support for those protocols, edit imapd.conf manually to include "tls_versions: tls1_0 tls1_1 tls1_2". New installations, however, will have an imapd.conf file that contains these settings already, i.e. newly installed IMAP servers do not support unsafe versions of SSL unless that support is explicitly enabled by the user. (bsc#901748)

  • An integer overflow vulnerability in cyrus-imapd's urlfetch range checking code was fixed. (CVE-2015-8076, CVE-2015-8077, CVE-2015-8078, bsc#981670, bsc#954200, bsc#954201)

  • Support for Elliptic Curve Diffie–Hellman (ECDH) has been added to cyrus-imapd. (bsc#860611)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Software Development Kit 11 SP4
    zypper in -t patch sdksp4-cyrus-imapd-12589=1
  • SUSE Linux Enterprise Server 11 SP4
    zypper in -t patch slessp4-cyrus-imapd-12589=1
  • SLES for SAP Applications 11-SP4
    zypper in -t patch slessp4-cyrus-imapd-12589=1

Package List:

  • SUSE Linux Enterprise Software Development Kit 11 SP4 (s390x x86_64 i586 ppc64 ia64)
    • cyrus-imapd-devel-2.3.11-60.65.67.1
  • SUSE Linux Enterprise Software Development Kit 11 SP4 (x86_64 i586)
    • perl-Cyrus-IMAP-2.3.11-60.65.67.1
    • perl-Cyrus-SIEVE-managesieve-2.3.11-60.65.67.1
  • SUSE Linux Enterprise Server 11 SP4 (s390x x86_64 i586 ppc64 ia64)
    • perl-Cyrus-IMAP-2.3.11-60.65.67.1
    • cyrus-imapd-2.3.11-60.65.67.1
    • perl-Cyrus-SIEVE-managesieve-2.3.11-60.65.67.1
  • SLES for SAP Applications 11-SP4 (ppc64 x86_64)
    • perl-Cyrus-IMAP-2.3.11-60.65.67.1
    • cyrus-imapd-2.3.11-60.65.67.1
    • perl-Cyrus-SIEVE-managesieve-2.3.11-60.65.67.1

References: