CVE-2024-49394

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 14, 2024
CWE ID 347

Summary

CVE-2024-49394 is a vulnerability affecting both mutt and neomutt email clients. This issue lies in the lack of cryptographic signing for the In-Reply-To email header field. An attacker can exploit this vulnerability by reusing an unencrypted but signed email message, allowing them to impersonate the original sender. This poses a significant risk for email spoofing and phishing attacks. Users are advised to update their email clients to the latest version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share