PT-2024-20004 · Tuta · Tuta
79Vt9V4
·
Published
2024-01-25
·
Updated
2024-01-31
·
CVE-2024-23655
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Tuta versions 3.118.12 through 3.119.9
Description
Tuta is an encrypted email service. An attacker can send a manipulated email to put the app into an unusable state, preventing the user from accessing received emails. This issue affects not only the app but also the web application, leaving the user with no way to access received emails. The issue was tested with iOS and the web app, but it is possible all clients are affected.
Recommendations
For versions 3.118.12 through 3.119.9, update to version 3.119.10 to resolve the issue. As a temporary workaround, consider avoiding the use of the affected email service until the update is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tuta