Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SciLinux: CVE-2011-1429 Moderate: Mutt i386/x86_64 Security Update

Scientific Large Esm H500
Moderate: mutt security update
Date: Wed, 20 Jul 2011 10:44:49 -0500
Reply-To: "Tyler L. Parsons" 
Sender: Security Errata for Scientific Linux
 
From: "Tyler L. Parsons" 
Subject: Security ERRATA Moderate: mutt on SL6.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 
MIME-Version: 1.0

Synopsis: Moderate: mutt security update
Issue Date: 2011-07-19
CVE Numbers: CVE-2011-1429

Mutt is a text-mode mail user agent.

A flaw was found in the way Mutt verified SSL certificates. When a server
presented an SSL certificate chain, Mutt could ignore a server hostname
check failure. A remote attacker able to get a certificate from a trusted
Certificate Authority could use this flaw to trick Mutt into accepting a
certificate issued for a different hostname, and perform man-in-the-middle
attacks against Mutt's SSL connections. (CVE-2011-1429)

All Mutt users should upgrade to this updated package, which contains a
backported patch to correct this issue. All running instances of Mutt must
be restarted for this update to take effect.

SL6:
 i386
 mutt-1.5.20-2.20091214hg736b6a.el6_1.1.i686.rpm
 mutt-debuginfo-1.5.20-2.20091214hg736b6a.el6_1.1.i686.rpm
 x86_64
 mutt-1.5.20-2.20091214hg736b6a.el6_1.1.x86_64.rpm
 mutt-debuginfo-1.5.20-2.20091214hg736b6a.el6_1.1.x86_64.rpm

- Scientific Linux Development Team
Your message here