UBUNTU-CVE-2018-14354
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-14354
UBUNTU-CVE-2018-14354
Summary:
Details: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.
References: https://ubuntu.com/security/CVE-2018-14354, https://github.com/neomutt/neomutt/commit/95e80bf9ff10f68cb6443f760b85df4117cb15eb, http://www.mutt.org/news.html, https://neomutt.org/2018/07/16/release, https://ubuntu.com/security/notices/USN-3719-1, https://ubuntu.com/security/notices/USN-3719-2, https://ubuntu.com/security/notices/USN-3719-3, https://www.cve.org/CVERecord?id=CVE-2018-14354, https://ubuntu.com/security/notices/USN-7204-1
Affected packages
Package
Name: mutt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
