MEDIUM
mutt: missing host name vs. SSL certificate name checks
Published Oct 23, 2009
6.8
MEDIUMCVSS 2.0
EPSS 1.14%
Description
mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected products
No data.
No data.
Red Hat Enterprise Linux 4
mutt
Will not fix
Red Hat Enterprise Linux 5
mutt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | mutt | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | mutt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- http://dev.mutt.org/trac/ticket/3087 x_refsource_CONFIRMPatchVendor Advisory
- http://marc.info/?l=oss-security&m=125198917018936&w=2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/26/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-3766 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=531011 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-3766
- https://www.cve.org/CVERecord?id=CVE-2009-3766
| Link | Providers | Tags |
|---|---|---|
| http://dev.mutt.org/trac/ticket/3087 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://marc.info/?l=oss-security&m=125198917018936&w=2 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2009/10/26/1 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2009-3766 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=531011 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-3766 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-3766 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2009
Updated Aug 7, 2024
Reserved Oct 23, 2009
Link CVE-2009-3766
CISA Vulnrichment
Updated n/a