In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
{
"binaries": [
{
"binary_name": "mutt",
"binary_version": "1.5.24-1ubuntu0.6+esm3"
},
{
"binary_name": "mutt-patched",
"binary_version": "1.5.24-1ubuntu0.6+esm3"
}
],
"priority_reason": "This is a longstanding limitation of PGP-encrypted mail and is an enhancement rather than an actual vulnerability."
}{
"binaries": [
{
"binary_name": "neomutt",
"binary_version": "20191207+dfsg.1-1.1ubuntu0.1~esm1"
}
],
"priority_reason": "This is a longstanding limitation of PGP-encrypted mail and is an enhancement rather than an actual vulnerability.",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_name": "neomutt",
"binary_version": "20211029+dfsg1-1ubuntu0.1~esm1"
}
],
"priority_reason": "This is a longstanding limitation of PGP-encrypted mail and is an enhancement rather than an actual vulnerability.",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_name": "neomutt",
"binary_version": "20231103+dfsg1-1ubuntu0.1~esm1"
}
],
"priority_reason": "This is a longstanding limitation of PGP-encrypted mail and is an enhancement rather than an actual vulnerability.",
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}