Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-49395

Опубликовано: 12 нояб. 2024
Источник: debian
EPSS Низкий

Описание

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
muttunfixedpackage
neomuttunfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2325332

  • https://gitlab.com/muttmua/mutt/-/issues/490

  • Mutt project does not plan to address CVE-2024-49393, CVE-2024-49394, CVE-2024-49395

  • cf. https://gitlab.com/muttmua/mutt/-/issues/490#note_2209448655 . Issues with documented

  • through http://mutt.org/doc/manual/#crypt-protected-headers-read

  • https://github.com/neomutt/neomutt/issues/4234

  • These are longstanding limitations of PGP-encrypted mail and rather enhancements

  • than actual vulnerabilities

EPSS

Процентиль: 30%
0.00108
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

CVSS3: 5.3
redhat
около 1 года назад

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

CVSS3: 5.3
nvd
около 1 года назад

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

CVSS3: 5.3
github
около 1 года назад

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

CVSS3: 5.3
fstec
больше 1 года назад

Уязвимость режима --hidden-recipient mode почтовых клиентов Mutt и NeoMutt, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 30%
0.00108
Низкий