CVE-2009-1390 describes a vulnerability in Mutt 1.5.19 when linked with OpenSSL or GnuTLS, where it fails to properly verify the entire TLS certificate chain, accepting connections if only one certificate in the chain is trusted. This flaw allows remote attackers to conduct man-in-the-middle (MitM) attacks to spoof trusted servers. The vulnerability has a CVSS score of 6.8 (Medium), indicating a network-based attack with medium complexity, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.19CPE matchmatch criteria | cpe:2.3:a:mutt:mutt:1.5.19:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.