CVE-2020-14954
MEDIUM EPSS 81.0%
Published Jun 21, 20206y ago · Modified Jun 17, 20262w ago
5.9 CVSS 3.1
Published Jun 21, 2020 6y ago
Last Modified Jun 17, 2026 2w ago
Description
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity High
Availability None
Threat Intelligence
EPSS Exploit Probability
81.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-74
Affected Products 14
| Vendor | Product | Version | Range |
|---|---|---|---|
| mutt | mutt | * | <1.14.4 |
| debian | debian_linux | 9.0 | any |
| debian | debian_linux | 10.0 | any |
| neomutt | neomutt | * | <20200619 |
| fedoraproject | fedora | 31 | any |
| fedoraproject | fedora | 32 | any |
| debian | debian_linux | 8.0 | any |
| canonical | ubuntu_linux | 12.04 | any |
| canonical | ubuntu_linux | 16.04 | any |
| canonical | ubuntu_linux | 18.04 | any |
| canonical | ubuntu_linux | 19.10 | any |
| canonical | ubuntu_linux | 20.04 | any |
| opensuse | leap | 15.1 | any |
| opensuse | leap | 15.2 | any |
References 16
- lists.mutt.org http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20200615/000023.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00064.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00070.html
- mutt.org http://www.mutt.org/
- github.com https://github.com/neomutt/neomutt/commit/fb013ec666759cb8a9e294347c7b4c1f597639cc
- github.com https://github.com/neomutt/neomutt/releases/tag/20200619
- gitlab.com https://gitlab.com/muttmua/mutt/-/commit/c547433cdf2e79191b15c6932c57f1472bfb5ff4
- gitlab.com https://gitlab.com/muttmua/mutt/-/issues/248
- lists.debian.org https://lists.debian.org/debian-lts-announce/2020/06/msg00039.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2020/06/msg00040.html
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EFMEILCBKMZRRZDMUGWLVN4PQQ4VTAZE/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3LXFVPTLK4PNHL6MPKJNJQJ25CH7GLQ/
- security.gentoo.org https://security.gentoo.org/glsa/202007-57
- usn.ubuntu.com https://usn.ubuntu.com/4403-1/
- debian.org https://www.debian.org/security/2020/dsa-4707
- debian.org https://www.debian.org/security/2020/dsa-4708
Remediation
- github.com https://github.com/neomutt/neomutt/commit/fb013ec666759cb8a9e294347c7b4c1f597639cc
- gitlab.com https://gitlab.com/muttmua/mutt/-/commit/c547433cdf2e79191b15c6932c57f1472bfb5ff4