Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
Link | Tags |
---|---|
http://www.mutt.org | product vendor advisory |
http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20200608/000022.html | mailing list vendor advisory |
https://bugs.gentoo.org/728300 | third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00064.html | vendor advisory broken link |
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00070.html | vendor advisory broken link |
https://usn.ubuntu.com/4401-1/ | third party advisory vendor advisory |
https://security.gentoo.org/glsa/202007-57 | third party advisory vendor advisory |