Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                  Note d'Information No. 2025/VULN075

_____________________________________________________________________

DATE                : 06/02/2025

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache James versions prior to
                                     3.8.2, 3.7.6.

=====================================================================
https://james.apache.org/james/update/2025/01/29/james-3.8.2.html
https://james.apache.org/james/update/2025/01/29/james-3.7.6.html
_____________________________________________________________________

Apache James Server 3.8.2
January 29, 2025

The Apache James developers are pleased to announce James server
3.8.2 release.

Early adopters can download it, any issue can be reported on our
issue tracker.

The Apache James PMC would like to thank all contributors who made
this release possible!


Announcement

This release comprise minor bug fixes enhancing Apache James
stability.

This release fixes the following security issues:

    CVE-2024-37358: Denial of service through the use of IMAP
literals

    CVE-2024-45626: Denial of service through JMAP HTML to text
conversion


Release changelog

The full changes included in this release can be seen in the CHANGELOG.

_____________________________________________________________________

Apache James Server 3.7.6
January 29, 2025

The Apache James developers are pleased to announce James server
3.7.6 release.

Early adopters can download it, any issue can be reported on our issue
tracker.

The Apache James PMC would like to thanks all contributors who made
this release possible!


Announcement

This release comprise minor bug fixes enhancing Apache James
stability.

This release fixes the following security issues:

    CVE-2024-37358: Denial of service through the use of IMAP literals

    CVE-2024-45626: Denial of service through JMAP HTML to text
conversion


Release changelog

The full changes included in this release can be seen in the
CHANGELOG.


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
