CVE-2020-14093: Medium severity Mutt Mutt vulnerability
Published Jun 15, 2020
·Updated
Last updated 25 August 2025
Other sources
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
— Launchpad
Affected Software
13 affected componentsFixes available
Mutt Mutt<1.14.3
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Leap=15.1
openSUSE Leap=15.2
debian/mutt
2.0.5-4.1+deb11u32.2.12-0.1~deb12u12.2.9-1+deb12u12.2.13-1
debian/neomutt
20201127+dfsg.1-1.220220429+dfsg1-4.120250510+dfsg-220260105+dfsg-1
Remediation
Event History
Jun 15, 2020
CVE Published
via MITRE·04:06 AM
Data Sourced
via MITRE·04:06 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:39 PM
Description
Feb 25, 2026
Data Sourced
via Ubuntu·07:26 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:27 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-14093?
The severity of CVE-2020-14093 is medium with a severity value of 5.9.
2
How does CVE-2020-14093 impact Mutt?
CVE-2020-14093 allows an IMAP fcc/postpone man-in-the-middle attack on Mutt before version 1.14.3.
3
How can I fix CVE-2020-14093?
To fix CVE-2020-14093, update Mutt to version 1.14.3 or later.
4
What is the Common Weakness Enumeration (CWE) for CVE-2020-14093?
The CWE for CVE-2020-14093 is CWE-319.
5
Where can I find more information about CVE-2020-14093?
You can find more information about CVE-2020-14093 on the following websites: http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00064.html, http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00070.html, http://www.mutt.org.