CVE-2009-1390: Medium severity mutt vulnerability
Mutt 1.5.19, when linked against (1) OpenSSL (muttssl.c) or (2) GnuTLS (muttsslgnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1390?
CVE-2009-1390 is considered a high severity vulnerability due to the risk of man-in-the-middle attacks.
How do I fix CVE-2009-1390?
To fix CVE-2009-1390, upgrade to the latest version of Mutt where the TLS certificate verification issue has been resolved.
What software is affected by CVE-2009-1390?
CVE-2009-1390 affects Mutt version 1.5.19 when linked against OpenSSL or GnuTLS.
What type of attack does CVE-2009-1390 facilitate?
CVE-2009-1390 facilitates man-in-the-middle attacks by allowing the acceptance of an incomplete TLS certificate chain.
What are the potential consequences of CVE-2009-1390?
The potential consequences of CVE-2009-1390 include the ability of remote attackers to spoof trusted servers.