Major vulnerabilities in opensmtpd resulting in RCE and DOS

Bug #1861242 reported by Ryan Kavanagh
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
opensmtpd (Debian)
Fix Released
Unknown
opensmtpd (Ubuntu)
Fix Released
Critical
Unassigned
Bionic
Fix Released
Critical
Unassigned
Eoan
Fix Released
Critical
Unassigned

Bug Description

opensmtpd versions >= 6 have two vulnerabilities:

An incorrect check allows an attacker to trick mbox delivery into executing
arbitrary commands as root and lmtp delivery into executing arbitrary commands
as an unprivileged user.

smtpd can crash on opportunistic TLS downgrade, causing a denial of service.

CVE References

Changed in opensmtpd (Debian):
status: Unknown → Confirmed
Revision history for this message
Colin Watson (cjwatson) wrote :

Ubuntu focal has 6.6.2p1-1 now as a result of an auto-sync from Debian. I've opened tasks for other series that have versions >= 6.

Changed in opensmtpd (Ubuntu Bionic):
status: New → Confirmed
importance: Undecided → Critical
Changed in opensmtpd (Ubuntu Eoan):
status: New → Confirmed
importance: Undecided → Critical
Changed in opensmtpd (Ubuntu):
status: Confirmed → Fix Released
information type: Public → Public Security
Revision history for this message
Ryan Kavanagh (ryanakca) wrote :

For bionic (6.0.3p1-1build1) and eoan (6.0.3p1-6), you'll want to cherry-pick the following two commits from debian/buster branch from the opensmtpd git packaging repo in Debian:

2483c1fceb8225a89e93901e9b5d182d576ac488
8cfa5131f89b8d454b65d152d98dfb863e00295a

https://salsa.debian.org/debian/opensmtpd/tree/debian/buster

I'm attaching these two commits as patches.

Revision history for this message
Ryan Kavanagh (ryanakca) wrote :
Changed in opensmtpd (Debian):
status: Confirmed → Fix Released
Ryan Kavanagh (ryanakca)
Changed in opensmtpd (Ubuntu Bionic):
status: Confirmed → Fix Released
Changed in opensmtpd (Ubuntu Eoan):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.