Back

MEDIUM

Mutt 1.5.19 SSL chain verification flaw

Published Jun 16, 2009

Description

Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of mutt as shipped with Red Hat Enterprise Linux 3, 4, or 5. Only mutt version 1.5.19 was affected by this flaw.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 16, 2009
Updated Aug 7, 2024
Reserved Apr 23, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 27, 2009
ENISA EUVD
Assigner redhat
Published Jun 16, 2009
Updated Aug 7, 2024
Exploited since n/a
EUVD-2009-1388