Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-28896

Опубликовано: 23 нояб. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 5.3

Описание

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.

РелизСтатусПримечание
bionic

released

1.9.4-3ubuntu0.4
devel

not-affected

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

1.9.4-3ubuntu0.4
esm-infra/focal

not-affected

1.13.2-1ubuntu0.3
esm-infra/xenial

not-affected

1.5.24-1ubuntu0.5
focal

released

1.13.2-1ubuntu0.3
groovy

released

1.14.6-1ubuntu0.1
hirsute

not-affected

impish

not-affected

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

20201120+dfsg.1-1
esm-apps/bionic

released

20171215+dfsg.1-1ubuntu0.1~esm1
esm-apps/focal

released

20191207+dfsg.1-1.1ubuntu0.1~esm1
esm-apps/jammy

not-affected

20201120+dfsg.1-1
esm-apps/noble

not-affected

20201120+dfsg.1-1
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life
hirsute

not-affected

20201120+dfsg.1-1

Показывать по

EPSS

Процентиль: 52%
0.00288
Низкий

2.6 Low

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 4 лет назад

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.

CVSS3: 5.3
nvd
больше 4 лет назад

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.

CVSS3: 5.3
debian
больше 4 лет назад

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $s ...

suse-cvrf
больше 4 лет назад

Security update for mutt

suse-cvrf
больше 4 лет назад

Security update for mutt

EPSS

Процентиль: 52%
0.00288
Низкий

2.6 Low

CVSS2

5.3 Medium

CVSS3