Bug#950411: mew: does not validate server certificate subject

2020-02-01 Thread Tatsuya Kinoshita
Control: clone -1 -2 Control: reassign -2 mew-beta Control: retitle -2 mew-beta: does not validate server certificate subject Control: found -2 7.0.50~6.7+0.20161225-1 Control: found -2 7.0.50~6.8+0.20190228-1 Control: fixed -2 7.0.50~6.8+0.20200130-1 The mew-beta package is also affected. Thank

Bug#950411: mew: does not validate server certificate subject

2020-02-01 Thread Tatsuya Kinoshita
Package: mew Version: 1:6.8-4 Severity: important Tags: security patch fixed-upstream Forwarded: https://github.com/kazu-yamamoto/Mew/pull/133 Control: found -1 1:6.7-4 Control: fixed -1 1:6.8-6 It was discovered that Mew, a mail reader in Emacs, performs insufficient validation of SSL/TLS certifi