In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Mutt | Mutt | - (including) | - (including) | 
| Neomutt | Neomutt | - (including) | - (including) | 
| Mutt | Ubuntu | devel | * | 
| Mutt | Ubuntu | esm-infra/bionic | * | 
| Mutt | Ubuntu | esm-infra/focal | * | 
| Mutt | Ubuntu | esm-infra/xenial | * | 
| Mutt | Ubuntu | focal | * | 
| Mutt | Ubuntu | jammy | * | 
| Mutt | Ubuntu | noble | * | 
| Mutt | Ubuntu | oracular | * | 
| Mutt | Ubuntu | plucky | * | 
| Mutt | Ubuntu | questing | * | 
| Neomutt | Ubuntu | esm-apps/bionic | * | 
| Neomutt | Ubuntu | esm-apps/focal | * | 
| Neomutt | Ubuntu | esm-apps/jammy | * | 
| Neomutt | Ubuntu | esm-apps/noble | * | 
| Neomutt | Ubuntu | focal | * | 
| Neomutt | Ubuntu | jammy | * | 
| Neomutt | Ubuntu | noble | * | 
| Neomutt | Ubuntu | oracular | * | 
| Neomutt | Ubuntu | upstream | * |