=========================================================================Ubuntu Security Notice USN-4517-1
September 17, 2020

libemail-address-list-perl vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Email-Address-List could be made to remotely exhaust resources if it
received specially crafted email data.

Software Description:
- libemail-address-list-perl: RFC close address list parsing

Details:

It was discovered that Email-Address-List does not properly parse email
addresses during email-ingestion. A remote attacker could use this issue
to cause an algorithmic complexity attack, resulting in a denial of
service. (CVE-2018-18898)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  libemail-address-list-perl      0.05-1+deb9u1build0.18.04.1

Ubuntu 16.04 LTS:
  libemail-address-list-perl      0.05-1+deb9u1build0.16.04.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4517-1
  CVE-2018-18898

Package Information:

https://launchpad.net/ubuntu/+source/libemail-address-list-perl/0.05-1+deb9u1build0.18.04.1

https://launchpad.net/ubuntu/+source/libemail-address-list-perl/0.05-1+deb9u1build0.16.04.1

Ubuntu: USN-4517-1 Email-Address-List vulnerability

September 18, 2020
Email-Address-List could be made to remotely exhaust resources if it received specially crafted email data.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libemail-address-list-perl 0.05-1+deb9u1build0.18.04.1 Ubuntu 16.04 LTS: libemail-address-list-perl 0.05-1+deb9u1build0.16.04.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4517-1

CVE-2018-18898

Severity
September 17, 2020

Package Information

https://launchpad.net/ubuntu/+source/libemail-address-list-perl/0.05-1+deb9u1build0.18.04.1 https://launchpad.net/ubuntu/+source/libemail-address-list-perl/0.05-1+deb9u1build0.16.04.1

Related News