CVE status and regression in 1.14.3 release
"Kevin J. McCarthy" <[email protected]> Sat, 20 Jun 2020 14:49:56 -0700
| Newsgroups | gmane.mail.mutt.announce |
|---|---|
| Message-ID | <[email protected]> |
--4ZLFUWh1odzi/v6L Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hello Mutt Users, Please pardon the "non-announcement" use of this list. I generally try=20 to keep the noise to a minimum, but felt this update was needed. The 1.14.3 release, fixing a possible IMAP PREAUTH injection attack, had=20 a regression. Those using $tunnel to an IMAP server may now encounter=20 an error "Encrypted connection unavailable" unless they change=20 $ssl_starttls. I've committed a fix:=20 <https://gitlab.com/muttmua/mutt/-/commit/dc909119b3433a84290f0095c0f43a23b= 98b3748>=20 but won't be able to make a release for 2-3 days. Packagers may wish to=20 apply the patch. Users encountering the problem should set=20 $ssl_starttls to "ask-yes", "ask-no", or "no" (with caution) for the=20 time being. In the release for 1.14.4, I promised a CVE number, but I have had no=20 success so far, despite waiting a day and submitting again. I may just=20 be doing something wrong, so if any packager with more experience=20 creating CVEs would like to do so for that release, I would greatly=20 appreciate it. (Perhaps also sending an email to mutt-dev, to avoid=20 multiple submissions). Thank you, -Kevin --4ZLFUWh1odzi/v6L Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAl7uhIQACgkQre92hIAx a9q7Kg/+I3AAcLFBaYvXlMUx8oSviU9VewejK/ezqtTpiaz9IVmnTKTW7tNB5rCE BbYbyRZ69dVn7zuQ8sIWWJkNE4RAwPzkS5RJoOBKZbYAO78S1j74XhvTqx0zrpbH noQWF83ViNGXMC9hYzYa+5OYNlz4or9b7OB7Cv98Hu4aYu9ZfcDhXErU+uUB+BuE vJHWsTdDqP5b+b13rNC/b6iPbRAijmMGzICE6TnftJFerFcRRtQLLZr8VtPkVQ2U B2I98PXHALMalTc6YTg/sfujc4l9w7lVCfwT+8+gRSnp6bWYLSluX3RaUZKA19no doFrdoMBOxnlDunJkGWfGCFGGfhAjAegqOlJJhrqpfIKghSTqfLBHu38szpvigmJ +qYii0vK/fIUy2IZ0H+sNUG8vn9hn/L3M7ji38uTBY3cofVbGMkHirv+Ej1UjpOD QkbZCsRL57iO1sHq6eQAYagDFzQAEUONd/6HMpNBjfQxgsOn3feij7UiKzYhyTxe m+b3B1YrETZWEZmVxB9OlxauTuHRjf+jtXygORP01uiXpfSAniruK+0lQWdgv4Cb Z53JrAnB9RuxBXW24+TaU0lD2j7VarJ0jdKQHZlEhtZjP8DZmlasnPOeYtUQCQUM siR6js6Yw8EQwcshtAwzCeTWj9rrfId97r8IUBtPjIBiXASboDk= =pvFs -----END PGP SIGNATURE----- --4ZLFUWh1odzi/v6L--