Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43420 | In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality. |
Ubuntu USN |
USN-7204-1 | NeoMutt vulnerabilities |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 16 Jul 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Sat, 05 Jul 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10 |
Thu, 14 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mutt
Mutt mutt Neomutt Neomutt neomutt |
|
| CPEs | cpe:2.3:a:mutt:mutt:-:*:*:*:*:*:*:* cpe:2.3:a:neomutt:neomutt:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mutt
Mutt mutt Neomutt Neomutt neomutt |
Tue, 12 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | mutt: neomutt: To and Cc email header fields are not protected by cryptographic signing | Mutt: neomutt: to and cc email header fields are not protected by cryptographic signing |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Tue, 12 Nov 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality. | |
| Title | mutt: neomutt: To and Cc email header fields are not protected by cryptographic signing | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T19:20:09.077Z
Reserved: 2024-10-14T17:56:03.767Z
Link: CVE-2024-49393
Updated: 2024-11-12T14:25:42.939Z
Status : Modified
Published: 2024-11-12T02:15:18.443
Modified: 2025-07-16T12:15:22.977
Link: CVE-2024-49393
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN