Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1429

Опубликовано: 16 мар. 2011
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00553
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 14 лет назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

redhat
больше 14 лет назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

debian
больше 14 лет назад

Mutt does not verify that the smtps server hostname matches the domain ...

github
около 3 лет назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

oracle-oval
почти 14 лет назад

ELSA-2011-0959: mutt security update (MODERATE)

EPSS

Процентиль: 67%
0.00553
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20