CVE-2024-49395

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-49395
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-49395.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-49395
Related
Published
2024-11-12T03:15:03Z
Modified
2024-11-20T21:50:51.799565Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

References

Affected packages

Debian:11 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.0.5-4.1
2.0.5-4.1+deb11u1
2.0.5-4.1+deb11u2
2.0.5-4.1+deb11u3
2.1.3-1
2.1.4-1
2.2.3-1
2.2.3-2
2.2.4-1
2.2.6-1
2.2.7-1
2.2.9-1
2.2.12-0.1~deb12u1
2.2.12-0.1
2.2.13-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.2.9-1
2.2.9-1+deb12u1
2.2.12-0.1~deb12u1
2.2.12-0.1
2.2.13-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.2.9-1
2.2.12-0.1~deb12u1
2.2.12-0.1
2.2.13-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20201127+dfsg.*

20201127+dfsg.1-1.2

Other

20211029+dfsg1-1
20220429+dfsg1-1
20220429+dfsg1-2
20220429+dfsg1-3
20220429+dfsg1-4
20231103+dfsg1-1
20240425+dfsg-1
20240425+dfsg-2
20241002+dfsg-1~bpo12+1
20241002+dfsg-1
20241114+dfsg-1

20220429+dfsg1-4.*

20220429+dfsg1-4.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20220429+dfsg1-4.*

20220429+dfsg1-4.1

Other

20231103+dfsg1-1
20240425+dfsg-1
20240425+dfsg-2
20241002+dfsg-1~bpo12+1
20241002+dfsg-1
20241114+dfsg-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20220429+dfsg1-4.*

20220429+dfsg1-4.1

Other

20231103+dfsg1-1
20240425+dfsg-1
20240425+dfsg-2
20241002+dfsg-1~bpo12+1
20241002+dfsg-1
20241114+dfsg-1

Ecosystem specific

{
    "urgency": "unimportant"
}