CVE-2009-3766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
23/10/2009
Last modified:
09/04/2025

Description

mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:* 1.5.16 (including) 1.5.19 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*