Re: mutt 1.14.4 released

2020-06-20 Thread Kevin J. McCarthy
On Sat, Jun 20, 2020 at 01:39:21AM +0200, Vincent Lefevre wrote: On 2020-06-20 08:48:04 +1000, Cameron Simpson wrote: On 19Jun2020 07:11, Kevin J. McCarthy wrote: Would it make more sense to just say "Warning: clearing unexpected buffered data after STARTTLS"? "Warning: after STARTTLS:

Re: mutt 1.14.4 released

2020-06-20 Thread Vincent Lefevre
On 2020-06-20 09:39:04 +0200, Petr Pisar wrote: > On Sat, Jun 20, 2020 at 01:39:21AM +0200, Vincent Lefevre wrote: > > On 2020-06-20 08:48:04 +1000, Cameron Simpson wrote: > > > On 19Jun2020 07:11, Kevin J. McCarthy wrote: > > > >On Fri, Jun 19, 2020 at 09:48:32AM +0200, Vincent Lefevre wrote: >

Re: mutt 1.14.4 released

2020-06-20 Thread Petr Pisar
On Sat, Jun 20, 2020 at 01:39:21AM +0200, Vincent Lefevre wrote: > On 2020-06-20 08:48:04 +1000, Cameron Simpson wrote: > > On 19Jun2020 07:11, Kevin J. McCarthy wrote: > > >On Fri, Jun 19, 2020 at 09:48:32AM +0200, Vincent Lefevre wrote: > > >>On 2020-06-18 18:14:15 -0700, Kevin J. McCarthy

Re: mutt 1.14.4 released

2020-06-19 Thread Vincent Lefevre
On 2020-06-20 08:48:04 +1000, Cameron Simpson wrote: > On 19Jun2020 07:11, Kevin J. McCarthy wrote: > >On Fri, Jun 19, 2020 at 09:48:32AM +0200, Vincent Lefevre wrote: > >>On 2020-06-18 18:14:15 -0700, Kevin J. McCarthy wrote: > >>+/* L10N: > >>+ The server is not supposed to send data

Re: mutt 1.14.4 released

2020-06-19 Thread Cameron Simpson
On 19Jun2020 07:11, Kevin J. McCarthy wrote: >On Fri, Jun 19, 2020 at 09:48:32AM +0200, Vincent Lefevre wrote: >>On 2020-06-18 18:14:15 -0700, Kevin J. McCarthy wrote: >>+/* L10N: >>+ The server is not supposed to send data immediately after >>+ confirming STARTTLS. This warns

Re: mutt 1.14.4 released

2020-06-19 Thread Kevin J. McCarthy
On Fri, Jun 19, 2020 at 09:48:32AM +0200, Vincent Lefevre wrote: On 2020-06-18 18:14:15 -0700, Kevin J. McCarthy wrote: +/* L10N: + The server is not supposed to send data immediately after + confirming STARTTLS. This warns the user that something + weird is going on. +

Re: mutt 1.14.4 released

2020-06-19 Thread Vincent Lefevre
On 2020-06-18 18:14:15 -0700, Kevin J. McCarthy wrote: > This is an important security release fixing a possible > machine-in-the-middle response injection attack when using STARTTLS with > IMAP, POP3, and SMTP. (For packagers, I've requested a CVE and will update > the website when I have the