CVE-2009-3766

NameCVE-2009-3766
Descriptionmutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mutt (PTS)stretch1.7.2-1+deb9u3fixed
stretch (security)1.7.2-1+deb9u5fixed
buster, buster (security)1.10.1-2.1+deb10u5fixed
bookworm, sid, bullseye2.0.5-4.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
muttsource(unstable)(not affected)

Notes

- mutt <not-affected> (uses GnuTLS and not OpenSSL)
our mutt is linked against gnutls, bug #553433

Search for package or bug name: Reporting problems