STARTTLS Buffering Issue in Mutt and NeoMutt Affecting Email Protocols
CVE-2020-14954
5.9MEDIUM
What is CVE-2020-14954?
The vulnerability in Mutt and NeoMutt arises from a STARTTLS buffering issue that impacts the handling of IMAP, SMTP, and POP3 protocols. When a server sends a 'begin TLS' response, the email client can inadvertently read additional data that could originate from a man-in-the-middle attacker, leading to potential response injection. This flaw underscores the importance of ensuring proper TLS handling to mitigate risks associated with malicious data interception during email communication.
