CVE-2009-3766: Medium severity mutt vulnerability
muttssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3766?
CVE-2009-3766 is classified as a moderate severity vulnerability due to its potential to allow man-in-the-middle attacks.
How does CVE-2009-3766 affect Mutt users?
CVE-2009-3766 affects Mutt users by not verifying the domain name in the Common Name field of X.509 certificates, making them vulnerable to spoofing attacks.
What versions of Mutt are impacted by CVE-2009-3766?
CVE-2009-3766 impacts Mutt versions from 1.5.16 to earlier than 1.5.19.
How do I fix CVE-2009-3766?
To fix CVE-2009-3766, upgrade Mutt to version 1.5.19 or later, which includes the necessary domain name verification fixes.
What can attackers do by exploiting CVE-2009-3766?
Exploiting CVE-2009-3766, attackers can perform man-in-the-middle attacks by spoofing SSL servers using valid but arbitrary certificates.