Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
[
{
"digest": {
"length": 1573.0,
"function_hash": "99262274997635620213827591474529996391"
},
"target": {
"file": "imap/imap.c",
"function": "imap_open_connection"
},
"source": "https://github.com/muttmua/mutt/commit/3e88866dc60b5fa6aaba6fd7c1710c12c1c3cd01",
"id": "CVE-2020-14093-6b7c5d7d",
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"329073539510483226673591755286140115782",
"9354916070945391285853520657590882211",
"279020998710288366256738070141285880900",
"42441136732123735428779836290913799504"
],
"threshold": 0.9
},
"target": {
"file": "imap/imap.c"
},
"source": "https://github.com/muttmua/mutt/commit/3e88866dc60b5fa6aaba6fd7c1710c12c1c3cd01",
"id": "CVE-2020-14093-e6266d78",
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false
}
]