MGASA-2013-0296
Dashboard / Vulnerabilities / MGASA-2013-0296
MGASA-2013-0296
Summary: Updated ssmtp package fixes security vulnerability
Details: It was reported that ssmtp, an extremely simple MTA to get mail off the system to a mail hub, did not perform x509 certificate validation when initiating a TLS connection to server. A rogue server could use this flaw to conduct man-in- the-middle attack, possibly leading to user credentials leak. As a result, alterations may be required to the configuration if using TLS. The default ssmtp.conf now contains the lines below to load root certificates which should be created as ssmtp.conf.rpmnew if it has been altered. #IMPORTANT: Uncomment the following line if you use TLS authentication #TLS_CA_File=/etc/pki/tls/certs/ca-bundle.crt
References: https://advisories.mageia.org/MGASA-2013-0296.html, https://bugs.mageia.org/show_bug.cgi?id=11148, https://lists.fedoraproject.org/pipermail/package-announce/2013-August/114906.html
Affected packages
Package
Name: ssmtp
Purl: pkg:rpm/mageia/ssmtp?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
