Buffer overflow in Mutt - CVE-2014-0467
Published: March 14, 2014 / Updated: July 28, 2020
Vulnerability identifier: #VU32554
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0467
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Affected software
Mutt
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
mutt (Alpine package)
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
mutt (Alpine package)
How to mitigate CVE-2014-0467
Install update from vendor's website.
Mutt - update to 1.5.23
mutt (Alpine package) - update to 1.5.23-r0
mutt (Alpine package) - update to 1.5.23-r0
External References
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00001.html
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00083.html
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00085.html
- http://rhn.redhat.com/errata/RHSA-2014-0304.html
- http://www.debian.org/security/2014/dsa-2874
- http://www.mutt.org/doc/devel/ChangeLog
- http://www.securityfocus.com/bid/66165
- http://www.securitytracker.com/id/1029919
- http://www.ubuntu.com/usn/USN-2147-1