CVE-2020-14954Injection in Mutt

Severity
5.9MEDIUMNVD
OSV9.8
EPSS
5.8%
top 9.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 21
Latest updateJan 15

Description

Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages7 packages

NVDneomutt/neomutt< 20200619
Debianneomutt/neomutt< 20200619+dfsg.1-1+3
Ubuntuneomutt/neomutt< 20171215+dfsg.1-1ubuntu0.1~esm1+3
NVDmutt/mutt< 1.14.4
Debianmutt/mutt< 1.14.4-1+3

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 31, 32, Ubuntu Linux 12.04, 16.04, 18.04, 19.10, 20.04

Patches

🔴Vulnerability Details

5
OSV
neomutt vulnerabilities2025-01-15
GHSA
GHSA-fv44-9w74-ffg5: Mutt before 12022-05-24
OSV
mutt vulnerability and regression2020-06-24
CVEList
CVE-2020-14954: Mutt before 12020-06-21
OSV
CVE-2020-14954: Mutt before 12020-06-21

📋Vendor Advisories

4
Ubuntu
NeoMutt vulnerabilities2025-01-15
Ubuntu
Mutt vulnerability and regression2020-06-24
Red Hat
mutt: response Injection via STARTTLS in SMTP, POP3 and IMAP2020-06-16
Debian
CVE-2020-14954: mutt - Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue...2020

💬Community

2
Bugzilla
CVE-2020-14954 mutt: response Injection via STARTTLS in SMTP, POP3 and IMAP2020-06-23
Bugzilla
CVE-2020-14954 mutt: response Injection via STARTTLS in SMTP, POP3 and IMAP [fedora-all]2020-06-23
CVE-2020-14954 — Injection in Mutt | cvebase