#VU14141 Command injection in Mutt - CVE-2018-14354
Published: July 31, 2018
Mutt
Mutt.org
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to command injection. A remote attacker can use IMAP servers to inject and execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.