REDHAT-BUG-2325332: Low severity mutt vulnerability
Published Nov 11, 2024
·Updated
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
Affected Software
2 affected components
Mutt Mutt
neomutt neomutt
Event History
Nov 11, 2024
Data Sourced
via Red Hat·09:39 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2325332?
The severity of REDHAT-BUG-2325332 is considered to be medium due to the potential leakage of Bcc email addresses.
2
How do I fix REDHAT-BUG-2325332?
To fix REDHAT-BUG-2325332, you should update Mutt or Neomutt to the latest version that addresses this vulnerability.
3
What is the impact of REDHAT-BUG-2325332?
The impact of REDHAT-BUG-2325332 is that it may expose Bcc recipient information to unintended parties during PGP encryption.
4
Which software is affected by REDHAT-BUG-2325332?
The software affected by REDHAT-BUG-2325332 includes Mutt and Neomutt.
5
Is REDHAT-BUG-2325332 a known vulnerability?
Yes, REDHAT-BUG-2325332 is a known vulnerability reported in the Red Hat Bugzilla.