package/mutt: security bump to version 2.0.7
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Fri, 21 May 2021 18:57:29 +0000 (20:57 +0200)
committerYann E. MORIN <yann.morin.1998@free.fr>
Fri, 21 May 2021 20:32:53 +0000 (22:32 +0200)
Fix CVE-2021-32055: Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt
2019-10-25 through 2021-05-04) has a $imap_qresync issue in which
imap/util.c has an out-of-bounds read in situations where an IMAP
sequence set ends with a comma. NOTE: the $imap_qresync setting for
QRESYNC is not enabled by default.

https://gitlab.com/muttmua/mutt/-/blob/mutt-2-0-7-rel/ChangeLog

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/mutt/mutt.hash
package/mutt/mutt.mk

index 8fccbd370985983eb6574533a7e6acaf7bfee419..6e1ca328517ea5d2d636d3db1d7e2dfb1a8d7ead 100644 (file)
@@ -1,3 +1,3 @@
 # Locally calculated
-sha256  81e31c45895fd624747f19106aa2697d2aa135049ff2e9e9db0a6ed876bcb598  mutt-2.0.6.tar.gz
+sha256  957688c6a521561992d4f2f27cf9feb239c7c6c0042c6061c0e474a7dd26cc91  mutt-2.0.7.tar.gz
 sha256  732f24b69a6c71cd8e01e4672bb8e12cc1cbb88a50a4665e6ca4fd95000a57ee  GPL
index 004a88d0b3b4bfce8b5e96fd042d96ad0c7bdca8..d7fcc01ad2aae7fb8f0be644dba6220b6c297782 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-MUTT_VERSION = 2.0.6
+MUTT_VERSION = 2.0.7
 MUTT_SITE = https://bitbucket.org/mutt/mutt/downloads
 MUTT_LICENSE = GPL-2.0+
 MUTT_LICENSE_FILES = GPL