First published: Mon Nov 11 2024(Updated: )
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
Affected Software | Affected Version | How to fix |
---|---|---|
Mutt | ||
Mutt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2325332 is considered to be medium due to the potential leakage of Bcc email addresses.
To fix REDHAT-BUG-2325332, you should update Mutt or Neomutt to the latest version that addresses this vulnerability.
The impact of REDHAT-BUG-2325332 is that it may expose Bcc recipient information to unintended parties during PGP encryption.
The software affected by REDHAT-BUG-2325332 includes Mutt and Neomutt.
Yes, REDHAT-BUG-2325332 is a known vulnerability reported in the Red Hat Bugzilla.