CVE Vulnerabilities

CVE-2024-49394

Improper Verification of Cryptographic Signature

Published: Nov 12, 2024 | Modified: Nov 14, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
MuttMutt- (including)- (including)
NeomuttNeomutt- (including)- (including)
MuttUbuntudevel*
MuttUbuntuesm-infra/bionic*
MuttUbuntuesm-infra/focal*
MuttUbuntuesm-infra/xenial*
MuttUbuntufocal*
MuttUbuntujammy*
MuttUbuntunoble*
MuttUbuntuoracular*
MuttUbuntuplucky*
MuttUbuntuquesting*
NeomuttUbuntuesm-apps/bionic*
NeomuttUbuntuesm-apps/focal*
NeomuttUbuntuesm-apps/jammy*
NeomuttUbuntuesm-apps/noble*
NeomuttUbuntufocal*
NeomuttUbuntujammy*
NeomuttUbuntunoble*
NeomuttUbuntuoracular*
NeomuttUbuntuupstream*

References