MEDIUM
Mutt 1.5.19 SSL chain verification flaw
Published Jun 16, 2009
6.8
MEDIUMCVSS 2.0
EPSS 1.92%
Description
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of mutt as shipped with Red Hat Enterprise Linux 3, 4, or 5. Only mutt version 1.5.19 was affected by this flaw.
Weaknesses (1)
References (11)
- http://dev.mutt.org/hg/mutt/rev/64bf199c8d8a x_refsource_CONFIRMExploitPatch
- http://dev.mutt.org/hg/mutt/rev/8f11dd00c770 x_refsource_CONFIRMExploit
- http://www.openwall.com/lists/oss-security/2009/06/10/2 mailing-listx_refsource_MLISTPatch
- http://www.securityfocus.com/bid/35288 vdb-entryx_refsource_BIDPatch
- https://access.redhat.com/security/cve/CVE-2009-1390 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=504979 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1388 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51068 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1390
- https://www.cve.org/CVERecord?id=CVE-2009-1390
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00715.html vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| http://dev.mutt.org/hg/mutt/rev/64bf199c8d8a | x_refsource_CONFIRMExploitPatch | |
| http://dev.mutt.org/hg/mutt/rev/8f11dd00c770 | x_refsource_CONFIRMExploit | |
| http://www.openwall.com/lists/oss-security/2009/06/10/2 | mailing-listx_refsource_MLISTPatch | |
| http://www.securityfocus.com/bid/35288 | vdb-entryx_refsource_BIDPatch | |
| https://access.redhat.com/security/cve/CVE-2009-1390 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=504979 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1388 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51068 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-1390 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-1390 | ||
| https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00715.html | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 16, 2009
Updated Aug 7, 2024
Reserved Apr 23, 2009
Link CVE-2009-1390
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1388 Assigner redhat
Published Jun 16, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1388