mutt: Incorrect handling of invalid initial IMAP responses could lead to an authentication attempt over unencrypted connection
Published Nov 23, 2020
5.3
MEDIUMCVSS 3.1
EPSS 2.35%
Description
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
mutt-5:2.0.7-1.el8
Fixed · RHSA-2021:4181
Red Hat Enterprise Linux 5
mutt
Out of support scope
Red Hat Enterprise Linux 6
mutt
Out of support scope
Red Hat Enterprise Linux 7
mutt
Out of support scope
Red Hat Enterprise Linux 9
mutt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | mutt-5:2.0.7-1.el8 | Fixed | RHSA-2021:4181 |
| Red Hat Enterprise Linux 5 | mutt | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | mutt | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | mutt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | mutt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated the severity of this flaw as Moderate because although the Confidentiality impact is high, the attack complexity is also high as a particular attacker would at least need to coordinate social engineering a victim to connect to a bad server, and also perform a man-in-the-middle attack or perform similar interception of the connection. Please see the following page for details on Red Hat severity ratings with special attention to Moderate: https://access.redhat.com/security/updates/classification .
References (11)
- https://access.redhat.com/security/cve/CVE-2020-28896 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1900826 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21287 Advisory
- https://github.com/neomutt/neomutt/commit/9c36717a3e2af1f2c1b7242035455ec8112b4b06 x_refsource_MISCPatchThird Party Advisory
- https://github.com/neomutt/neomutt/releases/tag/20201120 x_refsource_MISCRelease NotesThird Party Advisory
- https://gitlab.com/muttmua/mutt/-/commit/04b06aaa3e0cc0022b9b01dbca2863756ebbf59a x_refsource_MISCPatchThird Party Advisory
- https://gitlab.com/muttmua/mutt/-/commit/d92689088dfe80a290ec836e292376e2d9984f8f x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/11/msg00048.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-28896
- https://security.gentoo.org/glsa/202101-32 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-28896
Change history (0)
No recorded changes yet.