CVE-2024-49394

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-49394
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49394.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-49394
Related
Published
2024-11-12T03:15:03Z
Modified
2024-11-20T21:50:51.176721Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

References

Affected packages

Debian:11 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.0.5-4.1
2.0.5-4.1+deb11u1
2.0.5-4.1+deb11u2
2.0.5-4.1+deb11u3
2.1.3-1
2.1.4-1
2.2.3-1
2.2.3-2
2.2.4-1
2.2.6-1
2.2.7-1
2.2.9-1
2.2.12-0.1~deb12u1
2.2.12-0.1
2.2.13-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.2.9-1
2.2.9-1+deb12u1
2.2.12-0.1~deb12u1
2.2.12-0.1
2.2.13-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.2.9-1
2.2.12-0.1~deb12u1
2.2.12-0.1
2.2.13-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20201127+dfsg.*

20201127+dfsg.1-1.2

Other

20211029+dfsg1-1
20220429+dfsg1-1
20220429+dfsg1-2
20220429+dfsg1-3
20220429+dfsg1-4
20231103+dfsg1-1
20240425+dfsg-1
20240425+dfsg-2
20241002+dfsg-1~bpo12+1
20241002+dfsg-1
20241114+dfsg-1

20220429+dfsg1-4.*

20220429+dfsg1-4.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20220429+dfsg1-4.*

20220429+dfsg1-4.1

Other

20231103+dfsg1-1
20240425+dfsg-1
20240425+dfsg-2
20241002+dfsg-1~bpo12+1
20241002+dfsg-1
20241114+dfsg-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20241002+dfsg-1

Affected versions

20220429+dfsg1-4.*

20220429+dfsg1-4.1

Other

20231103+dfsg1-1
20240425+dfsg-1
20240425+dfsg-2
20241002+dfsg-1~bpo12+1

Ecosystem specific

{
    "urgency": "unimportant"
}