Re: Cyrus IMAP 3.8.3, 3.6.5, and 3.4.8 released

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi!

Ok the final and good test result with only a few minutes uptime. Running here on one backend a 3.4.8 with this patch in a murder with a 3.4.7 mupdate and some other backends.

Thanks Elli, I would say it is ok :)

Are there some special tests I can do to proof this?

@Jean: my "said not us before it said us" was the result on installing 3.8. on a bigger 3.4. Our way to upgrade would be a xfer to a new server. But I know this xfer will break down several times and a reconstruct can not find or fix problems before this xfer. But hopefully the xfer will not fail that often.

Zitat von Stephan Lauffer <lauffer@xxxxxxxxxxxxxx>:

Need to update and corret a bit:

Did a mistake and tested a 3.8. on a system where 3.4 must run.

So until now it is unclear if it woll work here. Tests results later this day.


Zitat von Stephan Lauffer <lauffer@xxxxxxxxxxxxxx>:

Dear Ellie,

thank's a lot for working on the patch.

We uses builds from https://download.opensuse.org/repositories/home:/buschmann23 and Matthias was so kind to add your patch to a branch for 3.4 and 3.8.

In our murder (atm all productive running on 3.4.7) I have two 3.8 backends. They only have a few boxes and there the patch worked fine.

But poorly it failed on a poduktive 3.4 (productive 3.4.7 and tested 3.4.8 with the patch). There we have about 6k users, ctl_mboxlist -v | wc -l says 82684.

'clt_mailboxlist -m' exits with a " fatal error: mupdate said not us before it said us".

I remember that I read a "said not us before it said us" years/months ago...

So at the moment I can not say that everything is fine now. Hm... :/

Matthias Fehring <buschmann@xxxxxxxxxxxxxxxxxx>



Zitat von ellie timoney <ellie@xxxxxxxxxxxx>:

Hi,

We've become aware that the fixes for CVE-2024-34055 break communications with the mupdate service in Cyrus Murder deployments (https://github.com/cyrusimap/cyrus-imapd/issues/4932)

We're working on a fix, and will publish new releases when it's ready. Murder deployments should avoid upgrading to the current versions, and wait for the next set of releases instead.

Sorry for the inconvenience,

ellie

On Wed, 5 Jun 2024, at 12:41 PM, ellie timoney wrote:
The Cyrus team is proud to announce the immediate availability of new versions of Cyrus IMAP: 3.8.3, 3.6.5, and 3.4.8

These releases contain a fix for CVE-2024-34055 <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34055>. From the release notes:

Cyrus-IMAP through 3.8.2 and 3.10.0-beta2 allow authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

The IMAP protocol allows for command arguments to be LITERALs of negotiated length, and for these the server allocates memory to receive the content before instructing the client to proceed. The allocated memory is released when the whole command has been received and processed.

The IMAP protocol has a number commands that specify an unlimited number of arguments, for example SEARCH. Each of these arguments can be a LITERAL, for which memory will be allocated and not released until the entire command has been received and processed. This can run a server out of memory, with varying consequences depending on the server's OOM policy.

Discovered by Damian Poddebniak.

This issue affects all previous Cyrus IMAP releases.

The updated versions introduce two new imapd.conf limits (maxargssize, maxliteral) that operators can configure with safe values for their environment. Please see the release notes and other documentation for full details.

These changes were too intrusive to backport to any earlier versions. If you are running Cyrus IMAP version 3.2 or earlier, we suggest upgrading to at least 3.4.8, especially if your service has untrusted users.

Release notes:

https://www.cyrusimap.org/3.8/imap/download/release-notes/3.8/x/3.8.3.html https://www.cyrusimap.org/3.6/imap/download/release-notes/3.6/x/3.6.5.html https://www.cyrusimap.org/3.4/imap/download/release-notes/3.4/x/3.4.8.html

Download URLs:

https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.8.3/cyrus-imapd-3.8.3.tar.gz https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.8.3/cyrus-imapd-3.8.3.tar.gz.sig

https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.6.5/cyrus-imapd-3.6.5.tar.gz https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.6.5/cyrus-imapd-3.6.5.tar.gz.sig

https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.4.8/cyrus-imapd-3.4.8.tar.gz https://github.com/cyrusimap/cyrus-imapd/releases/download/cyrus-imapd-3.4.8/cyrus-imapd-3.4.8.tar.gz.sig

On behalf of the Cyrus team,

ellie timoney
*Cyrus <https://cyrus.topicbox.com/latest>* / Announce / see discussions <https://cyrus.topicbox.com/groups/announce> + participants <https://cyrus.topicbox.com/groups/announce/members> + delivery options <https://cyrus.topicbox.com/groups/announce/subscription> Permalink <https://cyrus.topicbox.com/groups/announce/Ta8e3998446caf7f8-M391040654da3fceae98932e3>

------------------------------------------
Cyrus: Info
Permalink: https://cyrus.topicbox.com/groups/info/Ta8e3998446caf7f8-M79810c97693535168cde8cef
Delivery options: https://cyrus.topicbox.com/groups/info/subscription



--
Liebe Gruesse, with best regards
Stephan Lauffer

Pedagogical University Freiburg - Germany
http://www.ph-freiburg.de/zik/
Fon/ Fax: +49 761 682 -559/ -486



--
Liebe Gruesse, with best regards
Stephan Lauffer

Pedagogical University Freiburg - Germany
http://www.ph-freiburg.de/zik/
Fon/ Fax: +49 761 682 -559/ -486



--
Liebe Gruesse, with best regards
Stephan Lauffer

Pedagogical University Freiburg - Germany
http://www.ph-freiburg.de/zik/
Fon/ Fax: +49 761 682 -559/ -486

Attachment: smime.p7s
Description: S/MIME-Signatur


------------------------------------------
Cyrus: Info
Permalink: https://cyrus.topicbox.com/groups/info/Ta8e3998446caf7f8-M762378236aa97776a44741f8
Delivery options: https://cyrus.topicbox.com/groups/info/subscription

[Index of Archives]     [Cyrus SASL]     [Squirrel Mail]     [Asterisk PBX]     [Video For Linux]     [Photo]     [Yosemite News]     [gtk]     [KDE]     [Gimp on Windows]     [Steve's Art]
  Powered by Linux