-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 20 Jun 2020 07:42:44 +0200 Source: neomutt Architecture: source Version: 20180716+dfsg.1-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Mutt maintainers <neomutt@packages.debian.org> Changed-By: Antonio Radici <antonio@debian.org> Changes: neomutt (20180716+dfsg.1-1+deb10u1) buster-security; urgency=high . * debian/patches: + security/CVE-2020-14093.patch: handle the relevant CVE by removing a potential MITM attack with IMAP. + security/handle-startts.patch: fixes a not yet published CVE where the socket was not completely cleared after STARTTLS Checksums-Sha1: 11681d2cb84e99bf99c0540955a4f8e5a4ea4764 2352 neomutt_20180716+dfsg.1-1+deb10u1.dsc 1de075eca761c77c5d207275114fb6a16e0675d5 2645389 neomutt_20180716+dfsg.1.orig.tar.gz 57f2dcce48a4c0ca601c04fb82114aaff08c86d6 20636 neomutt_20180716+dfsg.1-1+deb10u1.debian.tar.xz e1e13569979c21e1d746842745aa169d1ffb00d9 8998 neomutt_20180716+dfsg.1-1+deb10u1_amd64.buildinfo Checksums-Sha256: 67c3220c37679158d7778e0bb6f023cea76f84a8ac6156ff0a59571cbe21a484 2352 neomutt_20180716+dfsg.1-1+deb10u1.dsc 26b5abfdd3d6c3383b84e2e7a3008a26d9cf5ddbc274181a2309c4528906962b 2645389 neomutt_20180716+dfsg.1.orig.tar.gz 11389ea8944284472ce84377c88d0897207b655a1c713d1e265d337d7362f2b0 20636 neomutt_20180716+dfsg.1-1+deb10u1.debian.tar.xz 920dcceb2bbdf97ae0e61d23099ede54984f422c2dec39f96a1fafe2c0875c4d 8998 neomutt_20180716+dfsg.1-1+deb10u1_amd64.buildinfo Files: c8e6f45e10008bb639e5c2cfc8ee4662 2352 mail optional neomutt_20180716+dfsg.1-1+deb10u1.dsc 15c3fa3cf334a181c946da361a260355 2645389 mail optional neomutt_20180716+dfsg.1.orig.tar.gz e6eeb087a97eceb66a303d7602f057a2 20636 mail optional neomutt_20180716+dfsg.1-1+deb10u1.debian.tar.xz ddc493e1578429df912d908327a67150 8998 mail optional neomutt_20180716+dfsg.1-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEQObYrBkA1SRrfOa1NcjIiHLLHu0FAl7uEDQTHGFudG9uaW9A ZGViaWFuLm9yZwAKCRA1yMiIcsse7S29D/9HvRdyg4vFIpKSo919jM5sQzL7LlPB /13oon5aERkhQRO4Pwd1XUWPavV0NqDVCHsrB1FaAOJ9VIS9JQ+W2tsI6kxyYglY wKHX8hGiiVT1SRok8d3ETdheL1F1lrBJSO6/NkXgbutHnn4FVpGrToeLs5EOTLYP MbnN+6DQ53LuQ/8TffXD8NL9psiDmN7yrOhPZGINKMA1YXJYBn/AUKhQeLUv1Lux c0v+yxCvVG8xg0wTxwZXTQjjGGcCNCoR0xvx+tmhPaUUzZmlpr34VC+x5esXYVvS cn4ZDTabstc9EPrWjlRIa2cDdRc23N6AF6ZONylJRnOo9H6YUFcxBsMQ29UfRHSL QYsfKsPOMcFhzfRIO1NsVDOLPxGm8lh0B7Sp/+rcXVfbyXAXgyXmtSIXfF94hNRI DRxbUUHgBmskKJw8Jenk9/Ys3T4VoCaQVDLFyoztbdyRULBH++gGPUNqx6uTqV1y hMcwGGZeBNdgO399V4wHhjzOiZHzqXGD/smhzRfvNjJi43L6tovyWHBg5kR9Ukrm M4d1Tpap2zdVVDH0wKCserDp3/cJtrjtmt8/+7y0zoEaraezPgMU48jHb4cigGSx v18zVotg1Hcz5zCxx7dEh7eiDXoZCihdVQbzl5sFJIBkHLjoWHVAfj/Yj5SknWI+ G+MinXQm+fMNNg== =S77T -----END PGP SIGNATURE-----