Path traversal in Mutt - CVE-2018-14363
Published: July 31, 2018
Mutt
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information cause DoS condition on the target system.
The vulnerability exists due to newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames. A remote attacker can conduct directory traversal attack and gain access to arbitrary data or cause the service to crash.