First published: Mon Nov 11 2024(Updated: )
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.
Affected Software | Affected Version | How to fix |
---|---|---|
Mutt | ||
Mutt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2325317 is high due to its potential impact on message confidentiality.
To fix REDHAT-BUG-2325317, update to the latest version of NeoMutt or Mutt where this vulnerability is addressed.
Users of NeoMutt and Mutt are affected by REDHAT-BUG-2325317.
REDHAT-BUG-2325317 enables an attacker to intercept and alter email headers, compromising the confidentiality of the message.
All versions of NeoMutt and Mutt prior to the patch for REDHAT-BUG-2325317 are susceptible to the vulnerability.