Improper input validation in Mutt - CVE-2018-14349
Published: July 31, 2018
Vulnerability identifier: #VU14136
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14349
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to mishandling of a NO response without a message in imap/command.c. A remote attacker can bypass security restrictions and conduct further attacks.
Affected software
Mutt
Arch Linux
Debian Linux
Gentoo Linux
Opensuse
Fedora
mutt (Alpine package)
mutt
Arch Linux
Debian Linux
Gentoo Linux
Opensuse
Fedora
mutt (Alpine package)
mutt
How to mitigate CVE-2018-14349
Update to version 1.10.1.
Mutt - update to 1.10.1
mutt (Alpine package) - update to 1.10.1-r0
mutt - addressed in versions 1.9.2-2.fc27, 1.10.1-1.fc28
mutt (Alpine package) - update to 1.10.1-r0
mutt - addressed in versions 1.9.2-2.fc27, 1.10.1-1.fc28