From 3e8c5eeb30bf2204896b77cf38c5aa90f0a611ac Mon Sep 17 00:00:00 2001 From: Derek Schrock Date: Fri, 20 Nov 2020 15:58:39 -0500 Subject: [PATCH] security/vuxml: add entries for mail/mutt 2.0.2 --- security/vuxml/vuln.xml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index d4bb1ef82..147dbb1f5 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,33 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + mutt -- authentication credentials being sent over an unencrypted connection + + + mutt + 2.0.2 + + + + +

Kevin J. McCarthy reports:

+
+

Mutt had incorrect error handling when initially connecting to an IMAP + server, which could result in an attempt to authenticate without enabling TLS.

+
+ +
+ + CVE-2020-28896 + https://gitlab.com/muttmua/mutt/-/commit/04b06aaa3e0cc0022b9b01dbca2863756ebbf59a + + + 2020-11-20 + 2020-11-20 + +
+ mozjpeg -- heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file -- 2.29.2