Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7: MGASA-2020-0448 Moderate: Mutt Authentication Issue

mageia
Calendar Grey December 5, 2020
Dist Mageia Esm H88
Mutt has released a set of package updates that tackle a serious security vulnerability related to unprotected connections. Discover further details about this advisory update.
Mutt before 2.0.2 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid

Summary

Mutt before 2.0.2 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle (CVE-2020-28896).

References

- https://bugs.mageia.org/show_bug.cgi?id=27686

- https://ubuntu.com/security/notices/USN-4645-1

- https://www.cve.org/CVERecord?id=CVE-2020-28896

Resolution

SRPMS

- 7/core/mutt-1.11.4-1.4.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 05 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0448.html
Type: security
CVE: CVE-2020-28896

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here