Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade mutt-debuginfoUpgrade mutt | Dec 7, 2022 | Jun 21, 2020 |
| Debian | — | Upgrade muttUpgrade neomutt | Jun 23, 2020 | Jun 21, 2020 |
| Freebsd | — | Upgrade mutt | Jun 25, 2020 | Jun 24, 2020 |
| Gentoo Linux | — | Upgrade mail-client/neomutt.Upgrade mail-client/mutt. | Jul 29, 2020 | Jun 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade mutt | Feb 22, 2021 | Jun 21, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade mutt | Sep 28, 2020 | Jun 21, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mutt | Nov 2, 2020 | Jun 21, 2020 |
| Oracle Solaris | — | Upgrade mail/mutt to version 1.14.5-11.4.27.0.1.82.0 on Solaris 11.4 | Jan 19, 2021 | Jun 21, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 21, 2020 |
| Suse | — | Upgrade neomutt-langUpgrade neomutt-docUpgrade muttUpgrade mutt-langUpgrade mutt-docUpgrade neomutt | Jun 27, 2020 | Jun 21, 2020 |
| Ubuntu | — | Upgrade muttUpgrade neomutt (Ubuntu Pro) | Jun 25, 2020 | Jun 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub