Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 60793 - mail-client/mutt Mutt PGP/GnuPG Verified Email Signature Spoofing Vulnerability
Summary: mail-client/mutt Mutt PGP/GnuPG Verified Email Signature Spoofing Vulnerability
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal
Assignee: Gentoo Security
URL: http://www.securityfocus.com/bid/10929
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-08-18 10:30 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2011-10-30 22:39 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-18 10:30:26 UTC
VULNERABILITIES
 



Mutt PGP/GnuPG Verified Email Signature Spoofing Vulnerability

 












It is reported that Mutt contains a vulnerability that allows attackers to send email that spoofs the look of a successfully verified PGP/GnuPG email message. 
 
An attacker may potentially simulate the look of the PGP/GnuPG output that Mutt usually includes when processing signed email messages. If a user employs Mutt with a specific configuration, the attacker may make email messages look almost identical to a properly signed and verified email. 
 
This may allow an attacker to create a message that falsifies a correctly verified PGP/GnuPG signature. This could allow an attacker to spoof email from trusted sources. This will likely greatly increase the effectiveness of social engineering attacks. 
 
In the index mode, messages with signatures have the 's' flag. Verified signatures change to 'S'. Ensuring that messages have the proper attributes will aid in the mitigation of this vulnerability. 
 
Versions 1.3.28 and 1.5.6 are reported affected by this vulnerability. Other versions are also likely affected.
Comment 1 Dan Margolis (RETIRED) gentoo-dev 2004-08-18 10:43:09 UTC
I think all this is supposed to be is formatting a message with something like 

------------------
verified signature
------------------

in it. Not really much the mutt guys or we can do about that, anyway. 

And I sorta doubt phishers are going to target mutt users, given that they aren't a huge subset of the population anyway.