FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Machine-in-the-middle response injection attack when using STARTTLS with IMAP, POP3, and SMTP

Affected packages
mutt <= 1.14.3

Details

VuXML ID 29b13a34-b1d2-11ea-a11c-4437e6ad11c4
Discovery 2020-06-16
Entry 2020-06-24

mutt 1.14.4 updates:

CVE-2020-14954 - Machine-in-the-middle response injection attack when using STARTTLS with IMAP, POP3, and SMTP

References

CVE Name CVE-2020-14954
URL https://gitlab.com/muttmua/mutt/-/commit/c547433cdf2e79191b15c6932c57f1472bfb5ff4