Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14154
Reference (s):
- GENTOO:GLSA-202007-57
- URL: https://security.gentoo.org/glsa/202007-57
- http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20200608/000022.html
- http://www.mutt.org
- https://bugs.gentoo.org/728300

