CVE-2024-49393
12.11.2024, 02:15
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.Enginsight
Vendor | Product | Version |
---|---|---|
mutt | mutt | - |
neomutt | neomutt | - |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mutt |
| ||||||||||||||
neomutt |
|
Common Weakness Enumeration