First published: Mon Nov 11 2024(Updated: )
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mutt Mutt | ||
Neomutt Neomutt | ||
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
debian/mutt | <=2.0.5-4.1+deb11u3<=2.2.12-0.1~deb12u1<=2.2.9-1+deb12u1<=2.2.13-1 | |
debian/neomutt | <=20201127+dfsg.1-1.2<=20220429+dfsg1-4.1 | 20241212+dfsg-2 20250109+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.