Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43422 | In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info. |
Sat, 05 Jul 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10 |
Thu, 14 Nov 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mutt
Mutt mutt Neomutt Neomutt neomutt |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mutt:mutt:-:*:*:*:*:*:*:* cpe:2.3:a:neomutt:neomutt:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mutt
Mutt mutt Neomutt Neomutt neomutt |
Tue, 12 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 Nov 2024 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | mutt: neomutt: Bcc email header field is indirectly leaked by cryptographic info block | Mutt: neomutt: bcc email header field is indirectly leaked by cryptographic info block |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Tue, 12 Nov 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info. | |
| Title | mutt: neomutt: Bcc email header field is indirectly leaked by cryptographic info block | |
| Weaknesses | CWE-1230 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-21T06:57:29.487Z
Reserved: 2024-10-14T17:56:03.767Z
Link: CVE-2024-49395
Updated: 2024-11-12T14:24:14.947Z
Status : Analyzed
Published: 2024-11-12T03:15:03.910
Modified: 2024-11-14T13:33:35.787
Link: CVE-2024-49395
OpenCVE Enrichment
No data.
EUVD