Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 32: 2020-1cb4c3697b Critical: Mutt Response Injection

fedora
Calendar Grey July 2, 2020
Dist Fedora Esm H88
The Mutt email client has implemented a patch for the CVE-2020-14954 flaw in Fedora 32, resolving concerns related to response injection vulnerabilities.
Security fix for CVE-2020-14954

Summary

Mutt is a small but very powerful text-based MIME mail client. Mutt

is highly configurable, and is well suited to the mail power user with

advanced features like key bindings, keyboard macros, mail threading,

regular expression searches and a powerful pattern matching language

for selecting groups of messages.

Security fix for CVE-2020-14954

* Wed Jun 24 2020 Fabio Alessandro Locati - 5:1.14.5-1

- Upgrade to 1.14.5

* Fri Jun 19 2020 Fabio Alessandro Locati - 5:1.14.4-1

- Upgrade to 1.14.4

- Resolves: #1848768

[ 1 ] Bug #1850170 - CVE-2020-14954 mutt: response Injection via STARTTLS in SMTP, POP3 and IMAP

https://bugzilla.redhat.com/show_bug.cgi?id=1850170

su -c 'dnf upgrade --advisory FEDORA-2020-1cb4c3697b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 1.14.5
Release: 1.fc32
Summary: A text mode mail user agent

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here