Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:3632-1

Опубликовано: 07 дек. 2020
Источник: suse-cvrf

Описание

Security update for mutt

This update for mutt fixes the following issues:

  • Find and display the content of messages properly. (bsc#1179461)
  • CVE-2020-28896: incomplete connection termination could send credentials over unencrypted connections. (bsc#1179035)
  • Avoid that message with a million tiny parts can freeze MUA for several minutes. (bsc#1179113)

Список пакетов

HPE Helion OpenStack 8
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-Azure
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-Azure-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-EC2-HVM
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-GCE
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-GCE-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-OCI-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP5-Azure-SAP-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP5-Azure-SAP-On-Demand
mutt-1.10.1-55.18.1
Image SLES12-SP5-EC2-SAP-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP5-EC2-SAP-On-Demand
mutt-1.10.1-55.18.1
Image SLES12-SP5-GCE-SAP-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP5-GCE-SAP-On-Demand
mutt-1.10.1-55.18.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
mutt-1.10.1-55.18.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
mutt-1.10.1-55.18.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
mutt-1.10.1-55.18.1
SUSE Enterprise Storage 5
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server 12 SP2-BCL
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server 12 SP2-LTSS
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server 12 SP3-BCL
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server 12 SP3-LTSS
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server 12 SP4-LTSS
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server 12 SP5
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
mutt-1.10.1-55.18.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
mutt-1.10.1-55.18.1
SUSE OpenStack Cloud 7
mutt-1.10.1-55.18.1
SUSE OpenStack Cloud 8
mutt-1.10.1-55.18.1
SUSE OpenStack Cloud 9
mutt-1.10.1-55.18.1
SUSE OpenStack Cloud Crowbar 8
mutt-1.10.1-55.18.1
SUSE OpenStack Cloud Crowbar 9
mutt-1.10.1-55.18.1

Описание

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.


Затронутые продукты
HPE Helion OpenStack 8:mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-Azure-BYOS:mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:mutt-1.10.1-55.18.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:mutt-1.10.1-55.18.1

Ссылки
Уязвимость SUSE-SU-2020:3632-1