Mutt SSL Certificate Validation Security Bypass Vulnerability
BID:36251
Info
Mutt SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 36251 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2008 12:00AM |
| Updated: | Sep 09 2009 06:01PM |
| Credit: | gkloepfer |
| Vulnerable: |
Mutt Mutt 1.5.19 Mutt Mutt 1.5.13 Mutt Mutt 1.5.12 Mutt Mutt 1.5.11 Mutt Mutt 1.5.10 Mutt Mutt 1.5.9 Mutt Mutt 1.5.6 Mutt Mutt 1.5.4 Mutt Mutt 1.5.3 Mutt Mutt 1.5.9i Mutt Mutt 1.5.5i Mutt Mutt 1.5.5.1i |
| Not Vulnerable: |
Mutt Mutt 1.5.20 |
Discussion
Mutt SSL Certificate Validation Security Bypass Vulnerability
Mutt is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from a server.
Successful exploits allow attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Versions prior to Mutt 1.5.20 are vulnerable.
Mutt is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from a server.
Successful exploits allow attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Versions prior to Mutt 1.5.20 are vulnerable.
Exploit / POC
Mutt SSL Certificate Validation Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Mutt SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Mutt SSL Certificate Validation Security Bypass Vulnerability
References:
References:
- #3087 (No server hostname validation in SSL certificate processing) (gkloepfer)
- Mutt Homepage (Mutt)