Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.5.24-1ubuntu0.3", "binary_name": "mutt" }, { "binary_version": "1.5.24-1ubuntu0.3", "binary_name": "mutt-dbg" }, { "binary_version": "1.5.24-1ubuntu0.3", "binary_name": "mutt-dbgsym" }, { "binary_version": "1.5.24-1ubuntu0.3", "binary_name": "mutt-patched" }, { "binary_version": "1.5.24-1ubuntu0.3", "binary_name": "mutt-patched-dbgsym" } ] }