CVE-2009-1390
published 2009-06-16CVE-2009-1390: Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.92%
77.8th percentile
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mutt | < mutt 1.5.20-1 (bookworm) | mutt 1.5.20-1 (bookworm) |
| mutt | mutt | — | — |
| mutt | mutt | >= 0 < 1.5.20-1 | 1.5.20-1 |
| mutt | mutt | >= 0 < 1.5.20-1 | 1.5.20-1 |
| mutt | mutt | >= 0 < 1.5.20-1 | 1.5.20-1 |
| mutt | mutt | >= 0 < 1.5.20-1 | 1.5.20-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j2p5-74xw-f54p: Mutt 1
ghsa_unreviewed·2022-05-02
CVE-2009-1390 [MEDIUM] CWE-287 GHSA-j2p5-74xw-f54p: Mutt 1
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
OSV
CVE-2009-1390: Mutt 1
osv·2009-06-16·CVSS 6.8
CVE-2009-1390 [MEDIUM] CVE-2009-1390: Mutt 1
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
Red Hat
Mutt 1.5.19 SSL chain verification flaw
vendor_redhat·2009-05-27·CVSS 6.8
CVE-2009-1390 [MEDIUM] Mutt 1.5.19 SSL chain verification flaw
Mutt 1.5.19 SSL chain verification flaw
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
Statement: Not vulnerable. This issue did not affect the versions of mutt as shipped with Red Hat Enterprise Linux 3, 4, or 5. Only mutt version 1.5.19 was affected by this flaw.
Debian
CVE-2009-1390: mutt - Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ss...
vendor_debian·2009·CVSS 6.8
CVE-2009-1390 [MEDIUM] CVE-2009-1390: mutt - Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ss...
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
Scope: local
bookworm: resolved (fixed in 1.5.20-1)
bullseye: resolved (fixed in 1.5.20-1)
forky: resolved (fixed in 1.5.20-1)
sid: resolved (fixed in 1.5.20-1)
trixie: resolved (fixed in 1.5.20-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3637 alienarena: Buffer overflow by processing specially-crafted UDP reply from game server (ACE)
bugzilla·2009-10-23·CVSS 10.0
CVE-2009-3637 [CRITICAL] CVE-2009-3637 alienarena: Buffer overflow by processing specially-crafted UDP reply from game server (ACE)
CVE-2009-3637 alienarena: Buffer overflow by processing specially-crafted UDP reply from game server (ACE)
Buffer overflow flaw was found in the way used to validate remote game servers
to be added into the server list. A remote attacker sending a specially-crafted
UDP reply from game server could execute arbitrary code on the side
and with the privileges of alienarena game client.
References:
http://www.ngssoftware.com/brochures/Anonymous.Remote.Arbitrary.Code.Execution.in.Alien.Arena.pdf (More descriptive issue details)
http://icculus.org/alienarena/changelogs/7.31.txt
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=552038
Upstream patch:
http://svn.icculus.org/alienarena/trunk/source/client/menu.c?r1=1383&r2=1391
(Merge o both revisions: 1390 and 1391, you might want to have a look
Bugzilla
CVE-2009-1390 Mutt 1.5.19 SSL chain verification flaw
bugzilla·2009-06-10·CVSS 6.8
CVE-2009-1390 [MEDIUM] CVE-2009-1390 Mutt 1.5.19 SSL chain verification flaw
CVE-2009-1390 Mutt 1.5.19 SSL chain verification flaw
Mutt version 1.5.19 introduced a support for intermediate CA certs,
available when mutt is linked against both OpenSSL and GnuTLS, added
via upstream commits:
http://dev.mutt.org/trac/changeset/5621:5db868a874b6/mutt_ssl.c
http://dev.mutt.org/trac/changeset/5623:7d0583e0315d/mutt_ssl_gnutls.c
Miroslav Lichvar noticed that a certificate chain validation was not
implemented properly. Individual certificates in the chain where
checked and accepted, but the chain as a whole as not validated
properly.
Issue was addressed via following upstream patches:
http://dev.mutt.org/trac/changeset?new=5870:dc9ec900c657@mutt_ssl.c&old=5699:1238dff54a15@mutt_ssl.c
http://dev.mutt.org/trac/changeset?new=5853:0b13183e40e0@mutt_ssl_gnutls.c&old=5699:12
arXiv
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
arxiv_fulltext·2025-11-27
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
UniBOM – A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
Vadim Safronov
Equal contribution.
[email protected]
University of Oxford
Oxford
United Kingdom
Ionut Bostan
[1]
[email protected]
NquiringMinds
Southampton
United Kingdom
Nicholas Allott
[email protected]
NquiringMinds
Southampton
United Kingdom
Andrew Martin
[email protected]
University of Oxford
Oxford
United Kingdom
Safronov et al.
## Abstract
Modern networked systems rely on complex software stacks, which often conceal vulnerabilities arising from intricate interdependencies. A Software Bill of Materials (SBOM) is effective for identifying dependencies and mitigating security risks. However, existing SBOM solutions lack precision, particularly in binary analysis a
http://dev.mutt.org/hg/mutt/rev/64bf199c8d8ahttp://dev.mutt.org/hg/mutt/rev/8f11dd00c770http://www.openwall.com/lists/oss-security/2009/06/10/2http://www.securityfocus.com/bid/35288https://exchange.xforce.ibmcloud.com/vulnerabilities/51068https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00715.htmlhttp://dev.mutt.org/hg/mutt/rev/64bf199c8d8ahttp://dev.mutt.org/hg/mutt/rev/8f11dd00c770http://www.openwall.com/lists/oss-security/2009/06/10/2http://www.securityfocus.com/bid/35288https://exchange.xforce.ibmcloud.com/vulnerabilities/51068https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00715.html
2009-06-16
Published