Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mutt | Jul 30, 2024 | Mar 16, 2011 |
| Freebsd | — | Upgrade mutt-devel | Dec 10, 2025 | Apr 6, 2012 |
| Oracle_linux | — | Upgrade mutt | Oct 16, 2024 | Mar 16, 2011 |
| Ubuntu | — | Upgrade mutt-patchedUpgrade mutt | Nov 8, 2024 | Mar 16, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub