Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-49393

Опубликовано: 11 нояб. 2024
Источник: redhat
CVSS3: 6.5

Описание

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10muttAffected
Red Hat Enterprise Linux 7muttOut of support scope
Red Hat Enterprise Linux 8muttAffected
Red Hat Enterprise Linux 9muttAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2325317mutt: neomutt: To and Cc email header fields are not protected by cryptographic signing

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

CVSS3: 6.5
nvd
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

CVSS3: 6.5
debian
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by ...

CVSS3: 7.4
github
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

CVSS3: 7.4
fstec
больше 1 года назад

Уязвимость почтовых клиентов Mutt и NeoMutt, связанная с ошибками проверки криптографической подписи, позволяющая нарушителю изменить список доверенных получателей и раскрыть защищаемую информацию

6.5 Medium

CVSS3