Publishing details
Changelog
mutt (1.10.1-2.1ubuntu0.2) eoan-security; urgency=medium
* SECURITY UPDATE: Man-in-the-middle attack
- debian/patches/CVE-2020-14954.patch: fix STARTTLS response injection
attack clearing the CONNECTION input buffer in mutt_ssl_starttls() in
mutt_socket.c, mutt_socket.h, mutt_ssl.c, mutt_ssl_gnutls.c.
- CVE-2020-14954
* Redoing patch CVE-2020-14154-1, that causes a possibly regression (LP: #1884588)
-- <email address hidden> (Leonidas S. Barbosa) Mon, 22 Jun 2020 15:27:39 -0300
Builds
Package files