REDHAT-BUG-2325317: Medium severity mutt vulnerability
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2325317?
The severity of REDHAT-BUG-2325317 is high due to its potential impact on message confidentiality.
How do I fix REDHAT-BUG-2325317?
To fix REDHAT-BUG-2325317, update to the latest version of NeoMutt or Mutt where this vulnerability is addressed.
Who is affected by REDHAT-BUG-2325317?
Users of NeoMutt and Mutt are affected by REDHAT-BUG-2325317.
What kind of attack does REDHAT-BUG-2325317 enable?
REDHAT-BUG-2325317 enables an attacker to intercept and alter email headers, compromising the confidentiality of the message.
What versions of NeoMutt and Mutt are sensitive to REDHAT-BUG-2325317?
All versions of NeoMutt and Mutt prior to the patch for REDHAT-BUG-2325317 are susceptible to the vulnerability.