Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
{ "vanir_signatures": [ { "deprecated": false, "id": "CVE-2020-14093-6b7c5d7d", "target": { "file": "imap/imap.c", "function": "imap_open_connection" }, "signature_version": "v1", "digest": { "function_hash": "99262274997635620213827591474529996391", "length": 1573.0 }, "source": "https://github.com/muttmua/mutt/commit/3e88866dc60b5fa6aaba6fd7c1710c12c1c3cd01", "signature_type": "Function" }, { "deprecated": false, "id": "CVE-2020-14093-e6266d78", "target": { "file": "imap/imap.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "329073539510483226673591755286140115782", "9354916070945391285853520657590882211", "279020998710288366256738070141285880900", "42441136732123735428779836290913799504" ], "threshold": 0.9 }, "source": "https://github.com/muttmua/mutt/commit/3e88866dc60b5fa6aaba6fd7c1710c12c1c3cd01", "signature_type": "Line" } ] }