Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43859

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 3.7

Описание

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

A flaw was found in mutt, an email client, where it mishandles cryptographic digests used for IMAP (Internet Message Access Protocol) authentication. This incorrect handling could lead to a low integrity impact, potentially allowing a remote attacker to subtly affect the authentication process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10muttFix deferred
Red Hat Enterprise Linux 6muttOut of support scope
Red Hat Enterprise Linux 7muttFix deferred
Red Hat Enterprise Linux 8muttFix deferred
Red Hat Enterprise Linux 9muttFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2464857mutt: Mutt: Low integrity impact in IMAP authentication due to cryptographic digest mishandling

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

CVSS3: 3.7
nvd
3 месяца назад

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

CVSS3: 3.7
debian
3 месяца назад

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMA ...

CVSS3: 3.7
github
3 месяца назад

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

suse-cvrf
около 2 месяцев назад

Security update for mutt

3.7 Low

CVSS3