VDB
CVE-2024-49393
CVE-2024-49393
PUBLISHED
Es existieren mehrere Schwachstellen in Mutt. Diese Fehler bestehen wegen unsachgemäßer kryptografischer Validierung und Konfiguration in der Verarbeitung von E-Mail-Headern und Verschlüsselungskomponenten. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um Daten zu manipulieren, die Vertraulichkeit von Nachrichten zu kompromittieren oder den ursprünglichen Absender zu imitieren.
EPSS 0.08% · 24.3th percentile
Risk Scores
EPSS Score
0.08%
24.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | |
| SUSE | SUSE openSUSE | |
| Ubuntu | Ubuntu Linux | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Open Source | Open Source mutt |
Exploit Intelligence
- CIRCL seen: CVE-2024-49393 (circl-sighting)
- https://access.redhat.com/security/cve/CVE-2024-49393 (circl)
- RHBZ#2325317 (circl)
Timeline
- Nov 12, 2024 EPSS Score
- Nov 12, 2024 Coalition ESS Score
- Nov 12, 2024 CVE Published
- Nov 12, 2024 PoC Published
- Nov 14, 2024 Coalition ESS Score
- Nov 14, 2024 Coalition ESS Score
- Nov 30, 2024 EPSS Score
- Dec 18, 2024 EPSS Score
- Jan 5, 2025 EPSS Score
- Jan 23, 2025 EPSS Score
- Feb 9, 2025 EPSS Score
- Feb 27, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3472.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3472 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2325317 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2325330 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2325332 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-49393 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-49394 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-49395 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/ZYFPGXOX4Q4I4UNPEGXP2N372IN2YSAS/ advisory
- https://ubuntu.com/security/notices/USN-7204-1 advisory