Summary: | <mail-client/mutt-1.10.1: Multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Fabian Groffen <grobian> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | grobian |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
See Also: | https://github.com/gentoo/gentoo/pull/9299 | ||
Whiteboard: | B2 [glsa+ cve] | ||
Package list: |
mail-client/mutt-1.10.1
mail-client/neomutt-20180716
|
Runtime testing required: | No |
Description
Fabian Groffen
2018-07-17 20:20:13 UTC
(In reply to Fabian Groffen from comment #0) > Heya, I'm pasting an email I got from the Mutt maintainer. Thanks, Fabian! I don't see an embargoe on the vulnerabilities so I am unrestricting the bug. Please CC arches when ready to stabilize. (In reply to Aaron Bauman from comment #1) > Thanks, Fabian! I don't see an embargoe on the vulnerabilities so I am > unrestricting the bug. Please CC arches when ready to stabilize. Yup, that was just me hoping to be on the safe side of things :) @arches: upstream maintainer ensured it is strongly recommended to update 1.10.1 is 1.10.1 without the security patches. Please stabilise mail-client/mutt-1.10.1 amd64 stable The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=93bce19a0929127a24610120482b690147eee6af commit 93bce19a0929127a24610120482b690147eee6af Author: Rolf Eike Beer <eike@sf-mail.de> AuthorDate: 2018-07-19 19:37:50 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-07-19 20:15:04 +0000 mail-client/mutt: stable 1.10.1 for sparc Bug: https://bugs.gentoo.org/661436 Package-Manager: Portage-2.3.40, Repoman-2.3.9 RepoMan-Options: --include-arches="sparc" mail-client/mutt/mutt-1.10.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=edfd9e96e510e03f350a2aff75c366ca96c69e9b commit edfd9e96e510e03f350a2aff75c366ca96c69e9b Author: Sergei Trofimovich <slyfox@gentoo.org> AuthorDate: 2018-07-20 08:02:02 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-07-20 08:07:32 +0000 mail-client/mutt: stable 1.10.1 for ia64, bug #661436 Bug: https://bugs.gentoo.org/661436 Package-Manager: Portage-2.3.43, Repoman-2.3.10 RepoMan-Options: --include-arches="ia64" mail-client/mutt/mutt-1.10.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) x86 stable The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=498e282df1cc634e75d4e19cce9fca5343f187cf commit 498e282df1cc634e75d4e19cce9fca5343f187cf Author: Sergei Trofimovich <slyfox@gentoo.org> AuthorDate: 2018-07-20 22:47:35 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-07-20 22:47:35 +0000 mail-client/mutt: stable 1.10.1 for ppc64, bug #661436 Bug: https://bugs.gentoo.org/661436 Package-Manager: Portage-2.3.43, Repoman-2.3.10 RepoMan-Options: --include-arches="ppc64" mail-client/mutt/mutt-1.10.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=647a0e4f10e8972115d196e0e0e17e56f5f7eadc commit 647a0e4f10e8972115d196e0e0e17e56f5f7eadc Author: Rolf Eike Beer <eike@sf-mail.de> AuthorDate: 2018-07-22 08:40:41 +0000 Commit: Sergei Trofimovich <slyfox@gentoo.org> CommitDate: 2018-07-22 09:00:08 +0000 mail-client/mutt: stable 1.10.1 for hppa Bug: https://bugs.gentoo.org/661436 Package-Manager: Portage-2.3.40, Repoman-2.3.9 RepoMan-Options: --include-arches="hppa" mail-client/mutt/mutt-1.10.1.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) arm stable Stable on alpha. New GLSA request filed. Looking good on ppc. Blocked packages are due to USE +libressl. # cat mutt-661436.report USE tests started on Do 30. Aug 23:43:11 CEST 2018 FEATURES=' test' USE='' succeeded for =mail-client/mutt-1.10.1 USE='-berkdb -crypt doc -gdbm -gnutls gpg -gpgme hcache idn -imap kerberos libressl lmdb mbox -nls nntp pgp_classic -pop -qdbm sasl -slang smime -smime_classic smtp -ssl -tokyocabinet -vanilla' : REQUIRED_USE not satisfied (probably) for =mail-client/mutt-1.10.1 USE='-berkdb crypt -doc -gdbm -gnutls -gpg gpgme -hcache -idn imap -kerberos libressl -lmdb -mbox -nls nntp pgp_classic -pop -qdbm sasl -slang smime smime_classic smtp -ssl -tokyocabinet -vanilla' : REQUIRED_USE not satisfied (probably) for =mail-client/mutt-1.10.1 USE tests started on Fr 31. Aug 12:01:51 CEST 2018 FEATURES=' test' USE='' succeeded for =mail-client/mutt-1.10.1 USE='-berkdb -crypt doc -gdbm -gnutls gpg -gpgme hcache idn -imap kerberos libressl lmdb mbox -nls nntp pgp_classic -pop -qdbm sasl -slang smime -smime_classic smtp -ssl -tokyocabinet -vanilla' : REQUIRED_USE not satisfied (probably) for =mail-client/mutt-1.10.1 USE='-berkdb crypt -doc -gdbm -gnutls -gpg gpgme -hcache -idn imap -kerberos libressl -lmdb -mbox -nls nntp pgp_classic -pop -qdbm sasl -slang smime smime_classic smtp -ssl -tokyocabinet -vanilla' : REQUIRED_USE not satisfied (probably) for =mail-client/mutt-1.10.1 USE='berkdb crypt doc gdbm gnutls -gpg gpgme hcache -idn -imap -kerberos libressl lmdb -mbox nls -nntp pgp_classic pop -qdbm sasl slang -smime -smime_classic -smtp ssl tokyocabinet -vanilla' succeeded for =mail-client/mutt-1.10.1 USE='berkdb crypt doc -gdbm -gnutls gpg -gpgme -hcache -idn -imap kerberos libressl -lmdb -mbox nls -nntp -pgp_classic pop qdbm sasl -slang -smime smime_classic smtp ssl tokyocabinet -vanilla' : blocked packages (probably) for =mail-client/mutt-1.10.1 USE='berkdb crypt doc -gdbm -gnutls gpg gpgme -hcache -idn imap kerberos libressl -lmdb mbox nls nntp pgp_classic -pop -qdbm sasl slang smime smime_classic -smtp -ssl -tokyocabinet vanilla' : REQUIRED_USE not satisfied (probably) for =mail-client/mutt-1.10.1 USE='-berkdb crypt -doc -gdbm -gnutls -gpg -gpgme -hcache -idn imap -kerberos -libressl lmdb -mbox -nls -nntp pgp_classic -pop qdbm sasl -slang smime -smime_classic -smtp ssl -tokyocabinet vanilla' succeeded for =mail-client/mutt-1.10.1 USE='berkdb crypt -doc -gdbm -gnutls gpg gpgme -hcache -idn imap kerberos libressl lmdb mbox -nls nntp pgp_classic -pop -qdbm sasl -slang -smime smime_classic smtp ssl -tokyocabinet vanilla' : blocked packages (probably) for =mail-client/mutt-1.10.1 USE='berkdb crypt doc gdbm -gnutls -gpg gpgme hcache -idn imap -kerberos libressl -lmdb mbox -nls -nntp pgp_classic -pop -qdbm sasl -slang -smime -smime_classic -smtp -ssl tokyocabinet vanilla' : REQUIRED_USE not satisfied (probably) for =mail-client/mutt-1.10.1 USE='berkdb crypt doc gdbm -gnutls gpg -gpgme hcache idn imap -kerberos libressl -lmdb -mbox -nls -nntp pgp_classic pop -qdbm sasl slang smime smime_classic -smtp -ssl tokyocabinet vanilla' : REQUIRED_USE not satisfied (probably) for =mail-client/mutt-1.10.1 USE='berkdb crypt doc gdbm gnutls gpg -gpgme hcache -idn -imap kerberos -libressl lmdb -mbox nls nntp pgp_classic pop qdbm -sasl -slang -smime -smime_classic -smtp ssl tokyocabinet vanilla' succeeded for =mail-client/mutt-1.10.1 USE='berkdb crypt doc -gdbm -gnutls gpg gpgme hcache -idn imap kerberos -libressl -lmdb -mbox -nls -nntp -pgp_classic pop qdbm sasl -slang smime -smime_classic -smtp ssl tokyocabinet vanilla' succeeded for =mail-client/mutt-1.10.1 USE='berkdb crypt doc gdbm -gnutls -gpg gpgme hcache idn imap -kerberos -libressl lmdb mbox nls -nntp -pgp_classic -pop qdbm -sasl slang smime -smime_classic -smtp ssl tokyocabinet vanilla' succeeded for =mail-client/mutt-1.10.1 ppc stable, thanks to ernsteiswuerfel! Adding mail-client/neomutt as it was missed. @arches, please stabilize. x86 stable amd64 stable @ Maintainer(s): Please cleanup and drop <mail-client/neomutt-20180716 and <mail-client/mutt-1.10.1! This issue was resolved and addressed in GLSA 201810-07 at https://security.gentoo.org/glsa/201810-07 by GLSA coordinator Thomas Deutschmann (whissi). Re-opening for cleanup. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=168b6360ba1239eac10847d1adce53af9ed17057 commit 168b6360ba1239eac10847d1adce53af9ed17057 Author: Fabian Groffen <grobian@gentoo.org> AuthorDate: 2018-10-31 08:57:05 +0000 Commit: Fabian Groffen <grobian@gentoo.org> CommitDate: 2018-10-31 08:57:05 +0000 mail-client/mutt: cleanup vulnerable versions, bug #661436 Bug: https://bugs.gentoo.org/661436 Signed-off-by: Fabian Groffen <grobian@gentoo.org> Package-Manager: Portage-2.3.49, Repoman-2.3.11 mail-client/mutt/Manifest | 6 - mail-client/mutt/metadata.xml | 1 - mail-client/mutt/mutt-1.7.2.ebuild | 274 --------------------------------- mail-client/mutt/mutt-1.9.4-r1.ebuild | 282 ---------------------------------- mail-client/mutt/mutt-1.9.5.ebuild | 282 ---------------------------------- 5 files changed, 845 deletions(-) |