Name | CVE-2020-14954 |
Description | Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection." |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-2268-1, DLA-2268-2, DSA-4707-1, DSA-4708-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
mutt (PTS) | bullseye (security), bullseye | 2.0.5-4.1+deb11u3 | fixed |
bookworm | 2.2.12-0.1~deb12u1 | fixed | |
bookworm (security) | 2.2.9-1+deb12u1 | fixed | |
sid, trixie | 2.2.13-1 | fixed | |
neomutt (PTS) | bullseye | 20201127+dfsg.1-1.2 | fixed |
bookworm | 20220429+dfsg1-4.1 | fixed | |
sid, trixie | 20241212+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
mutt | source | jessie | 1.5.23-3+deb8u3 | DLA-2268-2 | ||
mutt | source | stretch | 1.7.2-1+deb9u3 | DSA-4707-1 | ||
mutt | source | buster | 1.10.1-2.1+deb10u2 | DSA-4707-1 | ||
mutt | source | (unstable) | 1.14.4-1 | |||
neomutt | source | buster | 20180716+dfsg.1-1+deb10u1 | DSA-4708-1 | ||
neomutt | source | (unstable) | 20200619+dfsg.1-1 |
https://gitlab.com/muttmua/mutt/commit/c547433cdf2e79191b15c6932c57f1472bfb5ff4
https://gitlab.com/muttmua/mutt/-/issues/248
https://github.com/neomutt/neomutt/commit/fb013ec666759cb8a9e294347c7b4c1f597639cc