Bug 688756
| Summary: | CVE-2011-1429 mutt: improper verification of X.509 certificates can lead to MITM attacks on SMTP SSL connections [fedora-all] | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Vincent Danen <vdanen> | ||||
| Component: | mutt | Assignee: | Honza Horak <hhorak> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
| Severity: | medium | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | 14 | CC: | hhorak, mlichvar, pertusus | ||||
| Target Milestone: | --- | Keywords: | Security, SecurityTracking | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Release Note | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2011-06-27 11:27:51 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | |||||||
| Bug Blocks: | 688755 | ||||||
| Attachments: |
|
||||||
|
Description
Vincent Danen
2011-03-17 22:14:28 UTC
Created attachment 487048 [details] proposed patch - always check peer cert The proposed patch is being consulted with upstream; joining the discussion available here: http://dev.mutt.org/trac/ticket/3506 Comment on attachment 487048 [details]
proposed patch - always check peer cert
patch proposed in the parent bug
F14 (FEDORA-2011-7751) and F15 (FEDORA-2011-7739) updates are stable, F13 is EOL, closing. |