Lucene search

K
freebsdFreeBSD49314321-7FD4-11E1-9582-001B2134EF46
HistoryMar 08, 2012 - 12:00 a.m.

mutt-devel -- failure to check SMTP TLS server certificate

2012-03-0800:00:00
vuxml.freebsd.org
10

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.003

Percentile

66.2%

Dave B reports on Full Disclosure:

It seems that mutt fails to check the validity of a SMTP
servers certificate during a TLS connection. […]
This means that an attacker could potentially MITM a
mutt user connecting to their SMTP server even when the
user has forced a TLS connection.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchmutt-devel< 1.5.21_4UNKNOWN

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.003

Percentile

66.2%