-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 17 Jun 2020 20:37:38 +0200 Source: mutt Architecture: source Version: 1.10.1-2.1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Mutt maintainers <mutt@packages.debian.org> Changed-By: Antonio Radici <antonio@debian.org> Changes: mutt (1.10.1-2.1+deb10u1) buster-security; urgency=high . * debian/patches: + added security/CVE-2020-14093.patch to fix the relevant CVE related to IMAP MITM attack via a PREAUTH response + added security/CVE-2020-14154.patch to fix the relevant CVE where mutt proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate. Checksums-Sha1: 01cea2f95a44a684ba82ecb0994b4242d9435c2a 2391 mutt_1.10.1-2.1+deb10u1.dsc 584c3a5cd604813749da4d90c8c457a143ccd746 4255890 mutt_1.10.1.orig.tar.gz 46c14adbefbde069cc4ff0a2f75d2466b25f7ffe 833 mutt_1.10.1.orig.tar.gz.asc 2d4526a8fae5a6671b552839c8ee4fcdcc64d6c6 64668 mutt_1.10.1-2.1+deb10u1.debian.tar.xz be30fdc05ef303373990f5341e0158ac10977119 8236 mutt_1.10.1-2.1+deb10u1_amd64.buildinfo Checksums-Sha256: afb473e5dc5780d4e65a4570755b7b479dbd447ab1b77ecf9e0231f409594a33 2391 mutt_1.10.1-2.1+deb10u1.dsc 734a3883158ec3d180cf6538d8bd7f685ce641d2cdef657aa0038f76e79a54a0 4255890 mutt_1.10.1.orig.tar.gz 0ce9cb23947de6b0f35f7fc5f6b228c04c679e09cc59aaf77f8484187dacdf40 833 mutt_1.10.1.orig.tar.gz.asc a0928f368a1a62772d78eee8e85017d5c67c672fef9bc6404fa28013748c7109 64668 mutt_1.10.1-2.1+deb10u1.debian.tar.xz b543c59896ae9c6f8079d66578808c7868fb33732a053c47663935f01bcb81d6 8236 mutt_1.10.1-2.1+deb10u1_amd64.buildinfo Files: f55cddc058813dea774e1bbb809136a6 2391 mail optional mutt_1.10.1-2.1+deb10u1.dsc f1564f81ed5f8bacb7e041edc71d5347 4255890 mail optional mutt_1.10.1.orig.tar.gz bfa174eda4de275d63d9cd35c87fd88d 833 mail optional mutt_1.10.1.orig.tar.gz.asc 54bd795d2e69da86dd2d44062087f867 64668 mail optional mutt_1.10.1-2.1+deb10u1.debian.tar.xz b5245d6d909513f04c63c1d7c956c235 8236 mail optional mutt_1.10.1-2.1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEQObYrBkA1SRrfOa1NcjIiHLLHu0FAl7rgHATHGFudG9uaW9A ZGViaWFuLm9yZwAKCRA1yMiIcsse7YWQEAC1xoNgFN8VCpzTm7mSaWKg7Piu/ECR D649tRWsp39HyPwWvpKPFeEltlky5aoA9cOfEWq3H37xwDlbg3ToS1lgBmHb5egw CSqpT04w4lQgiunGzxvm60fDIeSjXG/R216f5LEgTYaSiuvJXjZeQfz7nlvkFyQq uyMH9+QLLudDXlvDnfMCgLrdUD5EMDn9ahm2roPMqfsW2bv/B6BvDqzail0pm6YW lh0to3b+T+mGjbHz7QJh1agk2jNSeHm5spSe9pB/zS04aArfKc5punawSECg+l6f eWqWdVK+RzEcRwl4RpULiABTV6oh3VzI/xKmI29jrIo1MtuxiSfWKO5kJIV7upxS JZGIvRQYk9N+egwfhZazg59RQ5L6NAyKk9oAkgTLHBA7rsMlDOtzwz2YUtFXHfw9 Po0ANVIdQ8bWtKPzPVzOd8kSfNATuN/pT1AnO7NZ+PhZTkxggP3KG38q984p9ZhD ups6N/jk0JFkktMx3LF7oJcCEm659XzYb3KYlUNKFbOj1amdcyEtVwAnuc9I1gWx RBF+rULqtCc8c3AfJemIlLCdCvoJKpuM1ulTlIe89t+f+YoRDgBhkLB8In/X/VUZ /LA8zm09BgRJY2dkcs6yj3006jueY729eglJUOsUYPCkFLQ7zexF6NPujGG+N+GC bINkVk91V8ntxg== =vKEP -----END PGP SIGNATURE-----