CVE-2009-3766

NameCVE-2009-3766
Descriptionmutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mutt (PTS)jessie, jessie (lts)1.5.23-3+deb8u7fixed
stretch (security)1.7.2-1+deb9u6fixed
stretch (lts), stretch1.7.2-1+deb9u7fixed
buster1.10.1-2.1+deb10u6fixed
buster (security)1.10.1-2.1+deb10u7fixed
bullseye (security), bullseye2.0.5-4.1+deb11u3fixed
bookworm2.2.12-0.1~deb12u1fixed
bookworm (security)2.2.9-1+deb12u1fixed
sid, trixie2.2.12-0.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
muttsource(unstable)(not affected)

Notes

- mutt <not-affected> (uses GnuTLS and not OpenSSL)
our mutt is linked against gnutls, bug #553433

Search for package or bug name: Reporting problems