Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2009-06-16 14:00
Updated : 2017-08-16 18:30
NVD link : CVE-2009-1390
Mitre link : CVE-2009-1390
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
openssl
- openssl
gnu
- gnutls
mutt
- mutt