← Back

CVE-2009-1390

nvd nist
Published: Jun 16, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.

Affected (1)

Products: Mutt: Mutt
1 product
Mutt
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 1.5.19
Running on/withPlatform Versions
Openssl
Openssl
All versions
Gnu
Gnutls
All versions

References (12)

Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.