uw-imap: patch CVE-2018-19518

Take patch from Debian from
873b07f46c

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 9f7c1e6bd101494c6cc5dad16a7fa65a13cbac70)
Signed-off-by: Anil Dongare <adongare@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
This commit is contained in:
Peter Marko 2025-11-21 10:52:55 -08:00 committed by Anuj Mittal
parent 77536efcb0
commit 2e768a8261
No known key found for this signature in database
GPG Key ID: 4340AEFE69F5085C
2 changed files with 25 additions and 0 deletions

View File

@ -0,0 +1,24 @@
uw-imap (8:2007f~dfsg-6) unstable; urgency=medium
* [CVE-2018-19518] 2013_disable_rsh.patch (new): Disable access to IMAP
mailboxes through running imapd over rsh, and therefore ssh (Closes:
#914632). Code using the library can enable it with tcp_parameters()
after making sure that the IMAP server name is sanitized.
-- Magnus Holmgren <holmgren@debian.org> Tue, 26 Feb 2019 23:35:43 +0100
CVE: CVE-2018-19518
Upstream-Status: Inactive-Upstream [lastrelease: 2007]
Signed-off-by: Peter Marko <peter.marko@siemens.com>
--- a/src/osdep/unix/Makefile
+++ b/src/osdep/unix/Makefile
@@ -988,7 +988,7 @@ onceenv:
-DMD5ENABLE=\"$(MD5PWD)\" -DMAILSPOOL=\"$(MAILSPOOL)\" \
-DANONYMOUSHOME=\"$(MAILSPOOL)/anonymous\" \
-DACTIVEFILE=\"$(ACTIVEFILE)\" -DNEWSSPOOL=\"$(NEWSSPOOL)\" \
- -DRSHPATH=\"$(RSHPATH)\" -DLOCKPGM=\"$(LOCKPGM)\" \
+ -DLOCKPGM=\"$(LOCKPGM)\" \
-DLOCKPGM1=\"$(LOCKPGM1)\" -DLOCKPGM2=\"$(LOCKPGM2)\" \
-DLOCKPGM3=\"$(LOCKPGM3)\" > OSCFLAGS
echo $(BASELDFLAGS) $(EXTRALDFLAGS) > LDFLAGS

View File

@ -15,6 +15,7 @@ SRC_URI = "https://fossies.org/linux/misc/old/imap-${PV}.tar.gz \
file://0001-Do-not-build-mtest.patch \
file://0002-tmail-Include-ctype.h-for-isdigit.patch \
file://0001-Fix-Wincompatible-function-pointer-types.patch \
file://CVE-2018-19518.patch \
"
SRC_URI[md5sum] = "2126fd125ea26b73b20f01fcd5940369"