{"id":"CVE-2011-1429","details":"Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.","modified":"2026-04-10T03:41:42.579455Z","published":"2011-03-16T22:55:04Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/44937"},{"type":"FIX","url":"http://seclists.org/fulldisclosure/2011/Mar/87"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061353.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061356.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061461.html"},{"type":"WEB","url":"http://securityreason.com/securityalert/8143"},{"type":"WEB","url":"http://www.redhat.com/support/errata/RHSA-2011-0959.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/46803"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66015"}],"schema_version":"1.7.5"}