PT-2011-3124 · Mutt+1 · Mutt+1

Published

2011-03-16

·

Updated

2017-08-17

·

CVE-2011-1429

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mutt (affected versions not specified)
Description The issue allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate. This is due to Mutt not verifying that the smtps server hostname matches the domain name of the subject of an X.509 certificate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-36964
AZL-7291
CVE-2011-1429
RHSA-2011:0959
RHSA-2011_0959

Affected Products

Mutt
Red Hat