Hello Mutt Users,I've just released version 2.0.2. Instructions for downloading are available at <http://www.mutt.org/download.html>, or the tarball can be directly downloaded from <http://ftp.mutt.org/pub/mutt/>. Please take the time to verify the signature file against my public key.
This is an important bug fix release, addressing CVE-2020-28896. Mutt had incorrect error handling when initially connecting to an IMAP server, which could result in an attempt to authenticate without enabling TLS.
Thanks to Gabriel Salles-Loustau for discovering the problem, and including detailed information and a reproducing example in his report!
Also thanks to Richard Russon for coordinating the release with Mutt. -Kevin
signature.asc
Description: PGP signature