GnuPG CVE-2018-12020 and Mutt

"Kevin J. McCarthy" <[email protected]> Sat, 9 Jun 2018 07:28:36 +0800
Newsgroups gmane.mail.mutt.announce
Message-ID <[email protected]>
--i7F3eY7HS/tUJxUd
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

Hi Mutt Users,

GnuPG just released an important security fix involving injection into
the status-fd channel.  The details are at
<https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html>.

If you are using the suggested values in contrib/gpg.rc, it should NOT
be necessary to switch to using GPGME (despite what they said in their
email).

Specifically make sure you have "--no-verbose" in $pgp_decode_command,
$pgp_verify_command, and $pgp_decrypt_command.

There are a couple other (non-critical) issues Marcus Brinkmann found
and reported to Mutt.  They are mitigated by the new GnuPG release, and
by fixes in Mutt's stable branch.  I will release a new stable version
in the next couple weeks.

-Kevin

--i7F3eY7HS/tUJxUd
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAlsbESMACgkQre92hIAx
a9q3DhAAumT1FMG8NzVLq0yl9F6u3i3FDaCtyM6rcQ7OG3g44jSR54XbBJPnMy3K
DupH79FyFx+R5yRVc19ToZld0W8XYUiMyA9vYEu3zab81gJhmiMrKhDYPlfg6xeQ
Mm+0ePCz9/y2Az3NS04jYug1t01whitRahKbbR2vAGVJTCU4z2SzJZFMBL/DrVc7
a4suKBA2BNwPmR2fJRX2L912iIulF8I8M6nAdh+fbofmUs3G5mDht+E+aduGW1qC
OoJu2YU6wW/YVTPsCFof6Ti9N/XSI+UXlI9aMgDazLez7T/qgPrq9rbOfKCuPBWv
GbrF9zdHbXUXQd6hg6tj3/9hbXvDbE2hfyJlIYg14SL1tjHaX42Cwt//fQQOnPtL
cJGxh8I+v19gRlhObOCbmR+8vUKriHuiXmyofeSyilBMa6kgrhzXLhNN5knB3YsH
2LwMbgYMr9roue+kIYJbr5vkgNDgMuoGVpYv6DTvoJdqr9lXz7claLK0oMUD32cY
6U+U/XJpEkPP03fqLMRaevDWu9VIH+KJH85OsseMhsESTEoob/152lulABs9fpYC
0a/EDyDh+Sf1onQeqKSdbYYdMBc59NbOZC88tSEAbBXGc5hNWzMz/MkRiPGVebMd
C4EOPPg9IxWYq78t5jwEYXGrAhvHOgwkI315bhxs+ADwQltrrqE=
=YsVX
-----END PGP SIGNATURE-----

--i7F3eY7HS/tUJxUd--