Lucene search

K
redhatRedHatRHSA-2011:0959
HistoryJul 19, 2011 - 12:00 a.m.

(RHSA-2011:0959) Moderate: mutt security update

2011-07-1900:00:00
access.redhat.com
14

EPSS

0.003

Percentile

66.2%

Mutt is a text-mode mail user agent.

A flaw was found in the way Mutt verified SSL certificates. When a server
presented an SSL certificate chain, Mutt could ignore a server hostname
check failure. A remote attacker able to get a certificate from a trusted
Certificate Authority could use this flaw to trick Mutt into accepting a
certificate issued for a different hostname, and perform man-in-the-middle
attacks against Mutt’s SSL connections. (CVE-2011-1429)

All Mutt users should upgrade to this updated package, which contains a
backported patch to correct this issue. All running instances of Mutt must
be restarted for this update to take effect.