PT-2024-10069 · Neomutt+2 · Neomutt+2

Published

2024-10-14

·

Updated

2024-11-14

·

CVE-2024-49395

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions mutt and neomutt (affected versions not specified)
Description The issue is related to PGP encryption in mutt and neomutt, where the --hidden-recipient mode is not used. This may lead to the leakage of the Bcc email header field by inferring from the recipients' information. The vulnerability can be exploited remotely, potentially allowing an attacker to disclose protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-00226
CVE-2024-49395

Affected Products

Debian
Mutt
Neomutt