MGASA-2020-0357

Source
https://advisories.mageia.org/MGASA-2020-0357.html
Import Source
https://advisories.mageia.org/MGASA-2020-0357.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0357
Related
Published
2020-09-02T08:01:16Z
Modified
2020-09-02T07:26:49Z
Summary
Updated mutt packages fix security vulnerabilities
Details

A potential IMAP Man-in-the-Middle attack via a PREAUTH response (CVE-2020-14093).

Mutt was ignoring an expired certificate and was proceeding with a connection (CVE-2020-14154).

A response injection due to a STARTTLS buffering issue which was affecting IMAP, SMTP, and POP3 (CVE-2020-14954).

References
Credits

Affected packages

Mageia:7 / mutt

Package

Name
mutt
Purl
pkg:rpm/mageia/mutt?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.11.4-1.3.mga7

Ecosystem specific

{
    "section": "core"
}