{"id":"AZL-7291","summary":"CVE-2011-1429 affecting package mutt 2.2.12-1","details":"Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.","modified":"2026-04-21T04:33:45.650367Z","published":"2011-03-16T22:55:04Z","upstream":["CVE-2011-1429"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1429"}],"affected":[{"package":{"name":"mutt","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/mutt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.2.12-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-7291.json"}}],"schema_version":"1.7.5"}