Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h64v-56v4-2q6j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

EPSS

Процентиль: 67%
0.00553
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 14 лет назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

redhat
больше 14 лет назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

nvd
больше 14 лет назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

debian
больше 14 лет назад

Mutt does not verify that the smtps server hostname matches the domain ...

oracle-oval
около 14 лет назад

ELSA-2011-0959: mutt security update (MODERATE)

EPSS

Процентиль: 67%
0.00553
Низкий

Дефекты

CWE-20