Back

MEDIUM

mutt: Incorrect handling of invalid initial IMAP responses could lead to an authentication attempt over unencrypted connection

Published Nov 23, 2020

Description

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated the severity of this flaw as Moderate because although the Confidentiality impact is high, the attack complexity is also high as a particular attacker would at least need to coordinate social engineering a victim to connect to a bad server, and also perform a man-in-the-middle attack or perform similar interception of the connection. Please see the following page for details on Red Hat severity ratings with special attention to Moderate: https://access.redhat.com/security/updates/classification .

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 23, 2020
Updated Aug 4, 2024
Reserved Nov 17, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 20, 2020
ENISA EUVD
Assigner mitre
Published Nov 23, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-21287