UBUNTU-CVE-2018-14362
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-14362
UBUNTU-CVE-2018-14362
Summary:
Details: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
References: https://ubuntu.com/security/CVE-2018-14362, https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e, http://www.mutt.org/news.html, https://neomutt.org/2018/07/16/release, https://ubuntu.com/security/notices/USN-3719-1, https://ubuntu.com/security/notices/USN-3719-2, https://ubuntu.com/security/notices/USN-3719-3, https://www.cve.org/CVERecord?id=CVE-2018-14362, https://ubuntu.com/security/notices/USN-7204-1
Affected packages
Package
Name: mutt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
