cbcvebase.
CVE-2024-49393
published 2024-11-12

CVE-2024-49393: In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.33%
25.3th percentile
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianmutt< neomutt 20241002+dfsg-1 (forky)neomutt 20241002+dfsg-1 (forky)
debianneomutt< neomutt 20241002+dfsg-1 (forky)neomutt 20241002+dfsg-1 (forky)
neomuttneomutt>= 0 < 20241002+dfsg-120241002+dfsg-1
neomuttneomutt>= 0 < 20241002+dfsg-120241002+dfsg-1
neomuttneomutt>= 0 < 20171215+dfsg.1-1ubuntu0.1~esm120171215+dfsg.1-1ubuntu0.1~esm1
neomuttneomutt>= 0 < 20191207+dfsg.1-1.1ubuntu0.1~esm120191207+dfsg.1-1.1ubuntu0.1~esm1
neomuttneomutt>= 0 < 20211029+dfsg1-1ubuntu0.1~esm120211029+dfsg1-1ubuntu0.1~esm1
neomuttneomutt>= 0 < 20231103+dfsg1-1ubuntu0.1~esm120231103+dfsg1-1ubuntu0.1~esm1
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.