First published: Mon Nov 11 2024(Updated: )
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
Affected Software | Affected Version | How to fix |
---|---|---|
Mutt | ||
Mutt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2325330 is classified as medium, due to the potential for impersonation of email senders.
To fix REDHAT-BUG-2325330, you should update to the latest version of Mutt or Neomutt where the vulnerability has been addressed.
Users of Mutt and Neomutt who handle email communications are affected by REDHAT-BUG-2325330.
Attackers can impersonate the original sender of emails by reusing signed but unencrypted email messages due to REDHAT-BUG-2325330.
Currently, there are no specific workarounds for REDHAT-BUG-2325330 other than updating the affected software.