Upstream information

CVE-2019-8337 at MITRE

Description

In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.

SUSE information

Overall state of this security issue: Does not affect SUSE products

SUSE Bugzilla entry: 1125420 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • msmtp >= 1.8.16-1.1
  • msmtp-doc >= 1.8.16-1.1
  • msmtp-lang >= 1.8.16-1.1
  • msmtp-mta >= 1.8.16-1.1
Patchnames:
openSUSE Tumbleweed GA msmtp-1.8.16-1.1