Bug 28296 - mutt new denial of service security issue (CVE-2021-3181). Is neomutt affected?
Summary: mutt new denial of service security issue (CVE-2021-3181). Is neomutt affected?
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL: https://www.openwall.com/lists/oss-se...
Whiteboard:
Keywords:
Depends on: 28159
Blocks:
  Show dependency treegraph
 
Reported: 2021-02-05 10:30 CET by Aurelien Oudelet
Modified: 2021-07-01 18:30 CEST (History)
3 users (show)

See Also:
Source RPM: neomutt-20180716-0.4.mga7.src.rpm
CVE: CVE-2021-3181
Status comment:


Attachments

Description Aurelien Oudelet 2021-02-05 10:30:14 CET
+++ This bug was initially created as a clone of Bug #28159 +++

A denial of service issue due to memory leak has been fixed upstream in mutt:
https://www.openwall.com/lists/oss-security/2021/01/17/2
CVE-2021-3181.

Mageia 7 affected and mutt patched.
This BR is for neomutt.

Assigning globally.
Cc'd recent commiters on it.
Aurelien Oudelet 2021-02-05 10:31:37 CET

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=28159

Aurelien Oudelet 2021-02-05 10:34:59 CET

Assignee: bugsquad => pkg-bugs
CC: mageia, qa-bugs, security => smelror
URL: (none) => https://www.openwall.com/lists/oss-security/2021/01/17/2
Keywords: advisory => (none)
Source RPM: mutt-1.11.4-1.4.mga7.src.rpm => neomutt-20180716-0.4.mga7.src.rpm

Comment 1 David Walser 2021-07-01 18:30:32 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.