shield
Security update for mutt
SUSE-SLE-Module-Basesystem-15-SP7-2026-2301
This update for mutt fixes the following issues - CVE-2026-43859: `strfcpy` used instead of `memcpy` for the IMAP `auth_cram` MD5 digest (bsc#1263897). - CVE-2026-43860: truncation of `hash_passwd` by one byte for IMAP `auth_cram` MD5 digest (bsc#1263896). - CVE-2026-43861: missing check for `\0` in `url_pct_decode` (bsc#1263895). - CVE-2026-43862: mishandling of the `imap_auth_gss` security level (bsc#1263894). - CVE-2026-43863: infinite loop in `data_object_to_stream` in `crypt-gpgme.c` (bsc#1263893). - CVE-2026-43864: NULL pointer dereference in function `show_sig_summary` (bsc#1263892).
-
Release DateJun 8 2026
-
ReferencesBugzilla: 1263892, 1263893, 1263894, 1263895, 1263896, 1263897, 1264047
CVEs: CVE-2026-43859, CVE-2026-43860, CVE-2026-43861, CVE-2026-43862, CVE-2026-43863, CVE-2026-43864 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
Basesystem Module 15.7 x86_64
-
Packages
Basesystem Module 15.7 s390x
-
Packages
Basesystem Module 15.7 aarch64
-
Packages
Basesystem Module 15.7 ppc64le
-
Packages