Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-49393

Опубликовано: 12 нояб. 2024
Источник: ubuntu
Приоритет: low
CVSS3: 6.5

Описание

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

РелизСтатусПримечание
devel

ignored

no fix planned
esm-infra/bionic

ignored

no fix planned
esm-infra/focal

ignored

no fix planned
esm-infra/xenial

ignored

no fix planned
focal

ignored

end of standard support, was ignored [no fix planned]
jammy

ignored

no fix planned
noble

ignored

no fix planned
oracular

ignored

end of life, was ignored [no fix planned]
plucky

ignored

no fix planned
questing

ignored

no fix planned

Показывать по

РелизСтатусПримечание
devel

not-affected

20241002+dfsg-1
esm-apps/bionic

ignored

changes too intrusive
esm-apps/focal

released

20191207+dfsg.1-1.1ubuntu0.1~esm1
esm-apps/jammy

released

20211029+dfsg1-1ubuntu0.1~esm1
esm-apps/noble

released

20231103+dfsg1-1ubuntu0.1~esm1
focal

ignored

end of standard support, was needed
jammy

needed

noble

needed

oracular

ignored

end of life, was needed
plucky

not-affected

20241002+dfsg-1

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

CVSS3: 6.5
nvd
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

CVSS3: 6.5
debian
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by ...

CVSS3: 7.4
github
около 1 года назад

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

CVSS3: 7.4
fstec
больше 1 года назад

Уязвимость почтовых клиентов Mutt и NeoMutt, связанная с ошибками проверки криптографической подписи, позволяющая нарушителю изменить список доверенных получателей и раскрыть защищаемую информацию

6.5 Medium

CVSS3