CVE-2024-49393
12.11.2024, 02:15
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mutt | mutt | - |
| neomutt | neomutt | - |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mutt |
| ||||||||||||||||
| neomutt |
|
Common Weakness Enumeration