Publishing details
Changelog
amavisd-new (1:2.13.0-3ubuntu1.1) mantic-security; urgency=medium
* SECURITY UPDATE: incorrect check via multiple boundary parameters
- debian/patches/CVE-2024-28054-1.patch: add CC_UNCHECKED,3 content
category in conf/amavisd.conf, lib/Amavis.pm, lib/Amavis/Conf.pm,
lib/Amavis/Unpackers.pm, lib/Amavis/Unpackers/MIME.pm,
lib/Amavis/Unpackers/Part.pm, t/Amavis/Unpackers/MIMETest.pm.
- debian/patches/CVE-2024-28054-2.patch: use
MIME::Entity->ambiguous_content if available in .gitlab-ci.yml,
lib/Amavis/Unpackers/MIME.pm.
- debian/patches/CVE-2024-28054-3.patch: describe CVE-2024-28054 in
README_FILES/README.CVE-2024-28054.
- CVE-2024-28054
-- Marc Deslauriers <email address hidden> Fri, 12 Apr 2024 11:03:05 -0400
Builds
Built packages
-
amavisd-new
Interface between MTA and virus scanner/content filters
-
amavisd-new-postfix
part of Ubuntu mail stack provided by Ubuntu server team
Package files