Bug 688756
Summary: | CVE-2011-1429 mutt: improper verification of X.509 certificates can lead to MITM attacks on SMTP SSL connections [fedora-all] | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Vincent Danen <vdanen> | ||||
Component: | mutt | Assignee: | Honza Horak <hhorak> | ||||
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | 14 | CC: | hhorak, mlichvar, pertusus | ||||
Target Milestone: | --- | Keywords: | Security, SecurityTracking | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Release Note | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2011-06-27 11:27:51 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | |||||||
Bug Blocks: | 688755 | ||||||
Attachments: |
|
Description
Vincent Danen
2011-03-17 22:14:28 UTC
Created attachment 487048 [details] proposed patch - always check peer cert The proposed patch is being consulted with upstream; joining the discussion available here: http://dev.mutt.org/trac/ticket/3506 Comment on attachment 487048 [details]
proposed patch - always check peer cert
patch proposed in the parent bug
F14 (FEDORA-2011-7751) and F15 (FEDORA-2011-7739) updates are stable, F13 is EOL, closing. |