CVE-2024-49394: Mutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/neomuttto a version that resolves this vulnerability.Fixed in 20250404+dfsg-2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49394?
CVE-2024-49394 is classified as a low severity vulnerability.
How does CVE-2024-49394 affect email security?
CVE-2024-49394 allows an attacker to impersonate the original sender by reusing an unencrypted but signed email message due to lack of cryptographic protection on the In-Reply-To email header.
How do I fix CVE-2024-49394?
To mitigate CVE-2024-49394, you should upgrade to the fixed versions of neomutt which are 20250113+dfsg-1 or later.
Which software is affected by CVE-2024-49394?
CVE-2024-49394 affects mutt and neomutt versions prior to their respective secure updates.
Is there a patch available for CVE-2024-49394?
Yes, a patch is available in the latest versions of neomutt and users are advised to update their installations to ensure security.