Mutt Does Non Properly Validate SMTP and IMAP Server TLS Certificates
|
|
SecurityTracker Alert ID: 1025807 |
|
SecurityTracker URL: http://securitytracker.com/id/1025807
|
|
CVE Reference:
CVE-2011-1429
(Links to External Site)
|
Date: Jul 20 2011
|
Impact:
Modification of authentication information, Modification of system information
|
Vendor Confirmed: Yes Exploit Included: Yes
|
|
Description:
A vulnerability was reported in Mutt. A remote user can conduct man-in-the-middle spoofing attacks.
The software does not validate a remote SMTP or IMAP server's TLS certificate. A remote user with the ability to conduct a man-in-the-middle attack can spoof a server to access the target user's TLS session.
Dave B reported this vulnerability.
|
Impact:
A remote user can conduct man-in-the-middle spoofing attacks.
|
Solution:
No solution was available at the time of this entry.
|
Vendor URL: www.mutt.org/ (Links to External Site)
|
Cause:
Authentication error
|
Underlying OS:
Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 20 Jul 2011 01:26:43 +0000
Subject: Mutt
|
CVE-2011-1429
|
|