Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
BID:36249
Info
Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 36249 |
| Class: | Design Error |
| CVE: |
CVE-2009-3765 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2009 12:00AM |
| Updated: | Apr 20 2011 07:24AM |
| Credit: | Tomas Hoger |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 11 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE openSUSE 10.3 Sun Solaris 11 Express S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Mutt Mutt 1.5.20 Mutt Mutt 1.5.19 |
| Not Vulnerable: | |
Discussion
Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Mutt is prone to a security-bypass vulnerability because the application fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successful exploits allow attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Mutt 1.5.20 is vulnerable; other versions may also be affected.
Mutt is prone to a security-bypass vulnerability because the application fails to properly validate the domain name in a signed CA certificate, allowing attackers to substitute malicious SSL certificates for trusted ones.
Successful exploits allow attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Mutt 1.5.20 is vulnerable; other versions may also be affected.
Exploit / POC
Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Attackers use man-in-the-middle attacks to exploit this issue.
Attackers use man-in-the-middle attacks to exploit this issue.
Solution / Fix
Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mutt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
References:
References:
- Changeset 6016:dc09812e63a3 for mutt_ssl.c (Tomas Hoger)
- CVE-2009-3765 Cryptographic Issues vulnerability in Mutt E-Mail Client (Oracle)
- Mutt Homepage (Mutt)