Описание
Security update for mutt
This update for mutt fixes the following issues
- CVE-2026-43859:
strfcpyused instead ofmemcpyfor the IMAPauth_cramMD5 digest (bsc#1263897). - CVE-2026-43860: truncation of
hash_passwdby one byte for IMAPauth_cramMD5 digest (bsc#1263896). - CVE-2026-43861: missing check for
\0inurl_pct_decode(bsc#1263895). - CVE-2026-43862: mishandling of the
imap_auth_gsssecurity level (bsc#1263894). - CVE-2026-43863: infinite loop in
data_object_to_streamincrypt-gpgme.c(bsc#1263893). - CVE-2026-43864: NULL pointer dereference in function
show_sig_summary(bsc#1263892).
Список пакетов
openSUSE Leap 16.0
mutt-2.2.16-160000.2.1
mutt-doc-2.2.16-160000.2.1
mutt-lang-2.2.16-160000.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1263892
- SUSE Bug 1263893
- SUSE Bug 1263894
- SUSE Bug 1263895
- SUSE Bug 1263896
- SUSE Bug 1263897
- SUSE Bug 1264047
- SUSE CVE CVE-2026-43859 page
- SUSE CVE CVE-2026-43860 page
- SUSE CVE CVE-2026-43861 page
- SUSE CVE CVE-2026-43862 page
- SUSE CVE CVE-2026-43863 page
- SUSE CVE CVE-2026-43864 page
Описание
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
Затронутые продукты
openSUSE Leap 16.0:mutt-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-doc-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-lang-2.2.16-160000.2.1
Ссылки
- CVE-2026-43859
- SUSE Bug 1263897
Описание
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
Затронутые продукты
openSUSE Leap 16.0:mutt-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-doc-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-lang-2.2.16-160000.2.1
Ссылки
- CVE-2026-43860
- SUSE Bug 1263896
Описание
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
Затронутые продукты
openSUSE Leap 16.0:mutt-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-doc-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-lang-2.2.16-160000.2.1
Ссылки
- CVE-2026-43861
- SUSE Bug 1263895
Описание
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
Затронутые продукты
openSUSE Leap 16.0:mutt-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-doc-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-lang-2.2.16-160000.2.1
Ссылки
- CVE-2026-43862
- SUSE Bug 1263894
Описание
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
Затронутые продукты
openSUSE Leap 16.0:mutt-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-doc-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-lang-2.2.16-160000.2.1
Ссылки
- CVE-2026-43863
- SUSE Bug 1263893
Описание
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
Затронутые продукты
openSUSE Leap 16.0:mutt-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-doc-2.2.16-160000.2.1
openSUSE Leap 16.0:mutt-lang-2.2.16-160000.2.1
Ссылки
- CVE-2026-43864
- SUSE Bug 1263892