5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): NONE
Mutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
References
- https://access.redhat.com/security/cve/CVE-2024-49394 x_refsource_REDHAT vdb-entry
- RHBZ#2325330 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-49394 x_refsource_REDHAT vdb-entry
- RHBZ#2325330 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-49394 x_refsource_REDHAT vdb-entry
- RHBZ#2325330 issue-tracking x_refsource_REDHAT
Affected products
Matching in nixpkgs
pkgs.neomutt
Small but very powerful text-based mail client
-
nixos-unstable -
- nixpkgs-unstable 20250510
pkgs.mutt-wizard
System for automatically configuring mutt and isync
-
nixos-unstable -
- nixpkgs-unstable 3.3.1
pkgs.notmuch-mutt
Mutt support for notmuch
-
nixos-unstable -
- nixpkgs-unstable 0.39
pkgs.font-mutt-misc
ClearU pcf fonts
-
nixos-unstable -
- nixpkgs-unstable 1.0.4
pkgs.pantheon.mutter
Window manager for GNOME
-
nixos-unstable -
- nixpkgs-unstable 46.8
pkgs.xorg.fontmuttmisc
ClearU pcf fonts
-
nixos-unstable -
- nixpkgs-unstable 1.0.4
Package maintainers
-
@rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org>
-
@mh182 Max Hofer <mh182@chello.at>
-
@SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com>
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>
-
@hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
-
@dasj19 Daniel Șerbănescu <daniel@serbanescu.dk>
-
@davidak David Kleuker <post@davidak.de>
-
@erikryb Erik Rybakken <erik.rybakken@math.ntnu.no>
-
@RaitoBezarius Ryan Lahfa <ryan@lahfa.xyz>
-
@ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>