CVE Vulnerabilities

CVE-2024-49393

Improper Verification of Cryptographic Signature

Published: Nov 12, 2024 | Modified: Nov 14, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
LOW

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Mutt Mutt - (including) - (including)
Neomutt Neomutt - (including) - (including)
Mutt Ubuntu devel *
Mutt Ubuntu esm-infra/bionic *
Mutt Ubuntu esm-infra/xenial *
Mutt Ubuntu focal *
Mutt Ubuntu jammy *
Mutt Ubuntu noble *
Mutt Ubuntu oracular *
Neomutt Ubuntu esm-apps/bionic *
Neomutt Ubuntu esm-apps/focal *
Neomutt Ubuntu esm-apps/jammy *
Neomutt Ubuntu esm-apps/noble *
Neomutt Ubuntu focal *
Neomutt Ubuntu jammy *
Neomutt Ubuntu noble *
Neomutt Ubuntu oracular *
Neomutt Ubuntu upstream *

References