Bug 28296

Summary: mutt new denial of service security issue (CVE-2021-3181). Is neomutt affected?
Product: Mageia Reporter: Aurelien Oudelet <ouaurelien>
Component: SecurityAssignee: All Packagers <pkg-bugs>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: luigiwalser, ouaurelien, smelror
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: https://www.openwall.com/lists/oss-security/2021/01/17/2
See Also: https://bugs.mageia.org/show_bug.cgi?id=28159
Whiteboard:
Source RPM: neomutt-20180716-0.4.mga7.src.rpm CVE: CVE-2021-3181
Status comment:
Bug Depends on: 28159    
Bug Blocks:    

Description Aurelien Oudelet 2021-02-05 10:30:14 CET
+++ This bug was initially created as a clone of Bug #28159 +++

A denial of service issue due to memory leak has been fixed upstream in mutt:
https://www.openwall.com/lists/oss-security/2021/01/17/2
CVE-2021-3181.

Mageia 7 affected and mutt patched.
This BR is for neomutt.

Assigning globally.
Cc'd recent commiters on it.
Aurelien Oudelet 2021-02-05 10:31:37 CET

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=28159

Aurelien Oudelet 2021-02-05 10:34:59 CET

Assignee: bugsquad => pkg-bugs
CC: mageia, qa-bugs, security => smelror
URL: (none) => https://www.openwall.com/lists/oss-security/2021/01/17/2
Keywords: advisory => (none)
Source RPM: mutt-1.11.4-1.4.mga7.src.rpm => neomutt-20180716-0.4.mga7.src.rpm

Comment 1 David Walser 2021-07-01 18:30:32 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED