Описание
Security update for mutt
This update for mutt fixes the following issues:
- CVE-2020-28896: incomplete connection termination could lead to sending credentials over unencrypted connections (bsc#1179035)
- Avoid that message with a million tiny parts can freeze MUA for several minutes (bsc#1179113)
Список пакетов
SUSE Linux Enterprise High Performance Computing 15-ESPOS
mutt-1.10.1-3.11.1
mutt-doc-1.10.1-3.11.1
mutt-lang-1.10.1-3.11.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
mutt-1.10.1-3.11.1
mutt-doc-1.10.1-3.11.1
mutt-lang-1.10.1-3.11.1
SUSE Linux Enterprise Module for Basesystem 15 SP1
mutt-1.10.1-3.11.1
mutt-doc-1.10.1-3.11.1
mutt-lang-1.10.1-3.11.1
SUSE Linux Enterprise Module for Basesystem 15 SP2
mutt-1.10.1-3.11.1
mutt-doc-1.10.1-3.11.1
mutt-lang-1.10.1-3.11.1
SUSE Linux Enterprise Server 15-LTSS
mutt-1.10.1-3.11.1
mutt-doc-1.10.1-3.11.1
mutt-lang-1.10.1-3.11.1
SUSE Linux Enterprise Server for SAP Applications 15
mutt-1.10.1-3.11.1
mutt-doc-1.10.1-3.11.1
mutt-lang-1.10.1-3.11.1
Ссылки
- Link for SUSE-SU-2020:3568-1
- E-Mail link for SUSE-SU-2020:3568-1
- SUSE Security Ratings
- SUSE Bug 1179035
- SUSE Bug 1179113
- SUSE CVE CVE-2020-28896 page
Описание
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:mutt-1.10.1-3.11.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:mutt-doc-1.10.1-3.11.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:mutt-lang-1.10.1-3.11.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:mutt-1.10.1-3.11.1
Ссылки
- CVE-2020-28896
- SUSE Bug 1179035