Описание
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mutt | unfixed | package | ||
| neomutt | unfixed | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2325332
https://gitlab.com/muttmua/mutt/-/issues/490
Mutt project does not plan to address CVE-2024-49393, CVE-2024-49394, CVE-2024-49395
cf. https://gitlab.com/muttmua/mutt/-/issues/490#note_2209448655 . Issues with documented
through http://mutt.org/doc/manual/#crypt-protected-headers-read
https://github.com/neomutt/neomutt/issues/4234
These are longstanding limitations of PGP-encrypted mail and rather enhancements
than actual vulnerabilities
EPSS
Связанные уязвимости
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
Уязвимость режима --hidden-recipient mode почтовых клиентов Mutt и NeoMutt, позволяющая нарушителю раскрыть защищаемую информацию
EPSS