PT-2011-3124 · Mutt+1 · Mutt+1

Publicado

2011-03-16

·

Atualizado

2017-08-17

·

CVE-2011-1429

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mutt (affected versions not specified)
Description The issue allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate. This is due to Mutt not verifying that the smtps server hostname matches the domain name of the subject of an X.509 certificate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-36964
AZL-7291
CVE-2011-1429
RHSA-2011:0959
RHSA-2011_0959

Produtos afetados

Mutt
Red Hat