VYPR
Unrated severityNVD Advisory· Published Jun 15, 2020· Updated Aug 4, 2024

CVE-2020-14093

CVE-2020-14093

Description

Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Mutt before 1.14.3 allows an IMAP man-in-the-middle attack via a PREAUTH response, enabling attackers to intercept emails saved to server.

Vulnerability

Mutt versions before 1.14.3 are vulnerable to a man-in-the-middle attack when handling IMAP connections [2]. The bug occurs during the initial connection: if the IMAP server sends a PREAUTH response before STARTTLS, Mutt may proceed with an unencrypted connection, allowing an attacker to inject a PREAUTH response [4]. This affects the fcc (file copy) and postpone features, used when saving or postponing emails to the server.

Exploitation

An attacker with network-level access to the IMAP connection can intercept the communication and send a PREAUTH response before TLS negotiation begins [2]. No authentication or user interaction beyond a normal IMAP connection is required. The attacker can then spoof the server and trick Mutt into saving emails to an attacker-controlled server [4].

Impact

Successful exploitation allows an attacker to redirect emails intended for the user's server to an attacker-controlled server, leading to disclosure of email content [2]. No credentials are exposed, but the confidentiality of saved emails is compromised [4].

Mitigation

The vulnerability is fixed in Mutt version 1.14.3 and later [2]. Ubuntu users can update via USN-4401-1 [2]. Gentoo users should upgrade to >=mail-client/mutt-1.14.4 [3]. No workarounds are available other than upgrading [4].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

32

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.