Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-11 Thread Antonio Radici
On Sun, Sep 10, 2023 at 09:59:53PM +0200, Sebastian Andrzej Siewior wrote: > Hi Antonio! > > On 2023-09-10 15:57:58 [+0200], Antonio Radici wrote: > > On Sun, Sep 10, 2023 at 01:38:33PM +0200, Salvatore Bonaccorso wrote: > > > Hi Antonio, > > > > > > FWIW, I have done the bookworm-security

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Sebastian Andrzej Siewior
Hi Antonio! On 2023-09-10 15:57:58 [+0200], Antonio Radici wrote: > On Sun, Sep 10, 2023 at 01:38:33PM +0200, Salvatore Bonaccorso wrote: > > Hi Antonio, > > > > FWIW, I have done the bookworm-security upload already to > > security-master, and still working on the bullseye-security one (with >

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Sebastian Andrzej Siewior
On 2023-09-10 15:57:13 [+0200], Antonio Radici wrote: Hi Antonio, > On Sun, Sep 10, 2023 at 01:47:30PM +0200, Salvatore Bonaccorso wrote: > > Hi Antonio, > > > > On Sun, Sep 10, 2023 at 01:24:10PM +0200, Antonio Radici wrote: > > > On Sun, Sep 10, 2023 at 01:05:31PM +0200, Antonio Radici wrote:

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Salvatore Bonaccorso
Hi Antonio, On Sun, Sep 10, 2023 at 03:57:58PM +0200, Antonio Radici wrote: > On Sun, Sep 10, 2023 at 01:38:33PM +0200, Salvatore Bonaccorso wrote: > > Hi Antonio, > > > > FWIW, I have done the bookworm-security upload already to > > security-master, and still working on the bullseye-security

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Antonio Radici
On Sun, Sep 10, 2023 at 01:47:30PM +0200, Salvatore Bonaccorso wrote: > Hi Antonio, > > On Sun, Sep 10, 2023 at 01:24:10PM +0200, Antonio Radici wrote: > > On Sun, Sep 10, 2023 at 01:05:31PM +0200, Antonio Radici wrote: > > > Thanks for raising this, I'm uploading the new packages with the fixes

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Antonio Radici
On Sun, Sep 10, 2023 at 01:38:33PM +0200, Salvatore Bonaccorso wrote: > Hi Antonio, > > FWIW, I have done the bookworm-security upload already to > security-master, and still working on the bullseye-security one (with > plan to release the DSA tonight ideally). Ack, thanks for the update, I

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Salvatore Bonaccorso
Hi, On Sun, Sep 10, 2023 at 01:38:33PM +0200, Salvatore Bonaccorso wrote: > Hi Antonio, > > On Sun, Sep 10, 2023 at 01:05:31PM +0200, Antonio Radici wrote: > > On Sat, Sep 09, 2023 at 10:23:32PM +0200, Salvatore Bonaccorso wrote: > > > Source: mutt > > > Version: 2.2.9-1 > > > Severity: grave >

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Salvatore Bonaccorso
Hi Antonio, On Sun, Sep 10, 2023 at 01:24:10PM +0200, Antonio Radici wrote: > On Sun, Sep 10, 2023 at 01:05:31PM +0200, Antonio Radici wrote: > > Thanks for raising this, I'm uploading the new packages with the fixes > > today. > > apparently someone else did a NMU with the new version and

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Salvatore Bonaccorso
Hi Antonio, On Sun, Sep 10, 2023 at 01:05:31PM +0200, Antonio Radici wrote: > On Sat, Sep 09, 2023 at 10:23:32PM +0200, Salvatore Bonaccorso wrote: > > Source: mutt > > Version: 2.2.9-1 > > Severity: grave > > Tags: security upstream > > Justification: user security hole > > X-Debbugs-Cc:

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Antonio Radici
On Sun, Sep 10, 2023 at 01:05:31PM +0200, Antonio Radici wrote: > Thanks for raising this, I'm uploading the new packages with the fixes today. apparently someone else did a NMU with the new version and incorrectly closed the bug. I reopened the bug because stable needs to be addressed (which I

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-10 Thread Antonio Radici
On Sat, Sep 09, 2023 at 10:23:32PM +0200, Salvatore Bonaccorso wrote: > Source: mutt > Version: 2.2.9-1 > Severity: grave > Tags: security upstream > Justification: user security hole > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > > Hi, > > The following vulnerabilities were

Bug#1051563: mutt: CVE-2023-4874 CVE-2023-4875

2023-09-09 Thread Salvatore Bonaccorso
Source: mutt Version: 2.2.9-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for mutt. CVE-2023-4874[0]: | Null pointer dereference when viewing a specially crafted