CVE-2009-3766
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
23/10/2009
Last modified:
09/04/2025
Description
mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:* | 1.5.16 (including) | 1.5.19 (excluding) |
| cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



