{"id":"MGASA-2020-0448","summary":"Updated mutt packages fix a security vulnerability","details":"Mutt before 2.0.2 did not ensure that $ssl_force_tls was processed if an IMAP\nserver's initial server response was invalid. The connection was not properly\nclosed, and the code could continue attempting to authenticate. This could\nresult in authentication credentials being exposed on an unencrypted\nconnection, or to a machine-in-the-middle (CVE-2020-28896).\n","modified":"2026-04-16T04:42:17.898584053Z","published":"2020-12-05T19:46:49Z","upstream":["CVE-2020-28896"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0448.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27686"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4645-1"}],"affected":[{"package":{"name":"mutt","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/mutt?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.4-1.4.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0448.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}