MGASA-2021-0070 - Updated mutt packages fix a security vulnerability

Publication date: 05 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0070.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2021-3181

It was discovered that Mutt incorrectly handled certain email messages.
An attacker could possibly use this issue to cause a denial of service because
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of
service (mailbox unavailability) by sending email messages with sequences of
semicolon characters in RFC822 address fields (aka terminators of empty groups).
(CVE-2021-3181).

mutt-1.11.4 has been patched for Mageia 7.

References:
- https://bugs.mageia.org/show_bug.cgi?id=28159
- https://www.openwall.com/lists/oss-security/2021/01/19/10
- https://www.openwall.com/lists/oss-security/2021/01/17/2
- https://www.debian.org/lts/security/2021/dla-2529
- https://ubuntu.com/security/notices/USN-4703-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3181

SRPMS:
- 7/core/mutt-1.11.4-1.5.mga7

Mageia 2021-0070: mutt security update

It was discovered that Mutt incorrectly handled certain email messages

Summary

It was discovered that Mutt incorrectly handled certain email messages. An attacker could possibly use this issue to cause a denial of service because rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). (CVE-2021-3181).
mutt-1.11.4 has been patched for Mageia 7.

References

- https://bugs.mageia.org/show_bug.cgi?id=28159

- https://www.openwall.com/lists/oss-security/2021/01/19/10

- https://www.openwall.com/lists/oss-security/2021/01/17/2

- https://www.debian.org/lts/security/2021/dla-2529

- https://ubuntu.com/security/notices/USN-4703-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3181

Resolution

MGASA-2021-0070 - Updated mutt packages fix a security vulnerability

SRPMS

- 7/core/mutt-1.11.4-1.5.mga7

Severity
Publication date: 05 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0070.html
Type: security
CVE: CVE-2021-3181

Related News