Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

openSUSE 15.2: 2020:2158-1 Moderate: Neomutt IMAP Breach

opensuse
Calendar Grey December 4, 2020
Dist Opensuse Esm H88
The latest neomutt update on openSUSE tackles several medium-level security vulnerabilities and enhances overall performance. A patch is provided.
An update that solves four vulnerabilities and has one errata is now available.

Description

This update for neomutt fixes the following issues:

Update neomutt to 20201120. Address boo#1179035, CVE-2020-28896.

* Security

- imap: close connection on all failures

* Features

- alias: add function to Alias/Query dialogs

- config: add validators for {imap,smtp,pop}_authenticators - config: warn when signature file is missing or not readable

- smtp: support for native SMTP LOGIN auth mech

- notmuch: show originating folder in index

* Bug Fixes

- sidebar: prevent the divider colour bleeding out

- sidebar: fix

- notmuch: fix query for current email

- restore shutdown-hook functionality

- crash in reply-to

- user-after-free in folder-hook

- fix some leaks

- fix application of limits to modified mailboxes

- write Date header when postponing

* Translations

- 100% Lithuanian

- 100% Czech

- 70% Turkish

* Docs

- Document that...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2020-2158=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

neomutt-20201120-bp152.2.3.1

- openSUSE Backports SLE-15-SP2 (noarch):

neomutt-doc-20201120-bp152.2.3.1

neomutt-lang-20201120-bp152.2.3.1

References

https://www.suse.com/security/cve/CVE-2020-14093.html

https://www.suse.com/security/cve/CVE-2020-14154.html

https://www.suse.com/security/cve/CVE-2020-14954.html

https://www.suse.com/security/cve/CVE-2020-28896.html

https://bugzilla.suse.com/1172906

https://bugzilla.suse.com/1172935

https://bugzilla.suse.com/1173197

https://bugzilla.suse.com/1179035

https://bugzilla.suse.com/1179113

--===============5317241724046297795=

Announcement ID: openSUSE-SU-2020:2158-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP2 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here