ALAS2023-2025-1117


Amazon Linux 2023 Security Advisory: ALAS2023-2025-1117
Advisory Released Date: 2025-08-08
Advisory Updated Date: 2025-08-08
Severity: Important

Issue Overview:

In Jakarta Mail 2.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages. (CVE-2025-7962)


Affected Packages:

jakarta-mail


Issue Correction:
Run dnf update jakarta-mail --releasever 2023.8.20250808 or dnf update --advisory ALAS2023-2025-1117 --releasever 2023.8.20250808 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
noarch:
    jakarta-mail-1.6.5-8.amzn2023.0.2.noarch

src:
    jakarta-mail-1.6.5-8.amzn2023.0.2.src