TROYANOSYVIRUS
Back to CVEs

CVE-2011-1429

N/A

Description

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

CVE Details

CVSS v3.1 ScoreN/A
Published3/16/2011
Last Modified4/29/2026
Sourcenvd
Honeypot Sightings0

Affected Products

mutt:mutt

Weaknesses (CWE)

CWE-20

References

http://seclists.org/fulldisclosure/2011/Mar/87(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/44937(af854a3a-2127-422b-91ae-364da2661108)
http://securityreason.com/securityalert/8143(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2011-0959.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/46803(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.