Synced 18 Jun 2026 05:58 UTC Account
← All products

CVE-2009-1390

MEDIUM severity · CVSS 6.8 · Improper authentication
6.8CVSS MEDIUM

Summary

Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impact
Exploit probability (EPSS)2%

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://dev.mutt.org/hg/mutt/rev/64bf199c8d8a ↗