PT-2024-20004 · Tuta · Tuta

79Vt9V4

·

Published

2024-01-25

·

Updated

2024-01-31

·

CVE-2024-23655

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tuta versions 3.118.12 through 3.119.9
Description Tuta is an encrypted email service. An attacker can send a manipulated email to put the app into an unusable state, preventing the user from accessing received emails. This issue affects not only the app but also the web application, leaving the user with no way to access received emails. The issue was tested with iOS and the web app, but it is possible all clients are affected.
Recommendations For versions 3.118.12 through 3.119.9, update to version 3.119.10 to resolve the issue. As a temporary workaround, consider avoiding the use of the affected email service until the update is applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-23655
GHSA-5H47-G927-629G

Affected Products

Tuta