PT-2020-3021 · Gnutls+4 · Mutt+4

Sam James

·

Published

2020-06-15

·

Updated

2024-06-15

·

CVE-2020-14154

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mutt versions prior to 1.14.3
Description The issue is related to incorrect certificate authentication. It may allow a remote attacker to perform a man-in-the-middle attack. If a user rejects an expired intermediate certificate in response to a GnuTLS certificate prompt, Mutt proceeds with the connection anyway.
Recommendations For versions prior to 1.14.3, update to version 1.14.3 or later to resolve the issue.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1100
BDU:2020-03244
CVE-2020-14154
OESA-2021-1399
OPENSUSE-SU-2020:0903-1
OPENSUSE-SU-2020:0915-1
OPENSUSE-SU-2020:2127-1
OPENSUSE-SU-2020:2157-1
OPENSUSE-SU-2020:2158-1
OPENSUSE-SU-2020_0903-1
OPENSUSE-SU-2020_0915-1
OPENSUSE-SU-2020_2127-1
OPENSUSE-SU-2024:11079-1
OPENSUSE-SU-2024:13279-1
SUSE-SU-2020:14414-1
SUSE-SU-2020:1771-1
SUSE-SU-2020:1794-1
USN-4401-1

Affected Products

Alt Linux
Linuxmint
Mutt
Suse
Ubuntu