CVE-2011-1429: Input Validation
Published Mar 16, 2011
·Updated
Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.
Affected Software
2 affected componentsFixes available
Mutt Mutt
Microsoft cbl2 mutt 2.2.12-1
Remediation
Patch Available
Event History
Mar 16, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Oct 1, 2025
Data Sourced
via Microsoft·11:10 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:10 PM
Affected Software
Updated
via Microsoft·11:10 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2011-1429?
CVE-2011-1429 is classified as a moderate severity vulnerability.
2
What impact does CVE-2011-1429 have on Mutt users?
CVE-2011-1429 allows man-in-the-middle attackers to spoof an SSL SMTP server, potentially compromising user data.
3
How can CVE-2011-1429 be mitigated in Mutt?
Users can mitigate CVE-2011-1429 by ensuring that they are using a version of Mutt that has implemented proper hostname verification.
4
Is there an available patch for CVE-2011-1429?
Yes, a patch addressing CVE-2011-1429 is available in the updated versions of Mutt.
5
What type of attack is associated with CVE-2011-1429?
CVE-2011-1429 is associated with man-in-the-middle attacks due to hostname verification issues.