package/mutt: fix CVE-2020-28896
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Mon, 21 Dec 2020 10:42:24 +0000 (11:42 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 23 Dec 2020 08:29:29 +0000 (09:29 +0100)
commit89a9f74fa85a8f0e080328393a356181033f4ad9
tree406be3c150f50e5e5588b0ad7cf382349183cba5
parent41bbe8df540e2c630ad04f8db7383a7e7705f368
package/mutt: fix CVE-2020-28896

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that
$ssl_force_tls was processed if an IMAP server's initial server response
was invalid. The connection was not properly closed, and the code could
continue attempting to authenticate. This could result in authentication
credentials being exposed on an unencrypted connection, or to a
machine-in-the-middle.

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/mutt/0001-Ensure-IMAP-connection-is-closed-after-a-connection-error.patch [new file with mode: 0644]
package/mutt/mutt.mk