Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mutt | Mutt | * | 1.14.3 (excluding) |
Mutt | Ubuntu | bionic | * |
Mutt | Ubuntu | devel | * |
Mutt | Ubuntu | eoan | * |
Mutt | Ubuntu | esm-infra/bionic | * |
Mutt | Ubuntu | esm-infra/focal | * |
Mutt | Ubuntu | esm-infra/xenial | * |
Mutt | Ubuntu | focal | * |
Mutt | Ubuntu | trusty | * |
Mutt | Ubuntu | xenial | * |