Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:2141-1

Опубликовано: 01 дек. 2020
Источник: suse-cvrf

Описание

Security update for mutt

This update for mutt fixes the following issues:

  • CVE-2020-28896: incomplete connection termination could lead to sending credentials over unencrypted connections (bsc#1179035)
  • Avoid that message with a million tiny parts can freeze MUA for several minutes (bsc#1179113)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.2
mutt-1.10.1-lp152.3.6.1
mutt-doc-1.10.1-lp152.3.6.1
mutt-lang-1.10.1-lp152.3.6.1

Описание

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.


Затронутые продукты
openSUSE Leap 15.2:mutt-1.10.1-lp152.3.6.1
openSUSE Leap 15.2:mutt-doc-1.10.1-lp152.3.6.1
openSUSE Leap 15.2:mutt-lang-1.10.1-lp152.3.6.1

Ссылки