CVE-2024-49395

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 14, 2024
CWE ID 1230

Summary

CVE-2024-49395 is a vulnerability affecting both mutt and neomutt email clients. The issue lies in the PGP encryption process, where the --hidden-recipient mode is not implemented. As a result, the Bcc (Blind Carbon Copy) email header field may be leaked, potentially exposing the email recipients' information. This vulnerability could lead to privacy concerns and potential security risks if an attacker gains access to the email traffic. Users are advised to update their mutt and neomutt clients to the latest version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share