Vulnerability CVE-2018-14362: Information

Description

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: July 17, 2018
Modified: May 19, 2020
Error type identifier: CWE-119

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
muttsisyphus1.10.1-alt12.1.1.0.3.g6c0f75cca-alt1ALT-PU-2018-2274-1212084Fixed
muttp101.10.1-alt12.1.1.0.3.g6c0f75cca-alt1ALT-PU-2018-2274-1212084Fixed
muttp91.10.1-alt11.10.1-alt2.p9.1ALT-PU-2018-2274-1212084Fixed
muttc10f11.10.1-alt12.1.1.0.3.g6c0f75cca-alt1ALT-PU-2018-2274-1212084Fixed
muttc9f21.10.1-alt11.10.1-alt2ALT-PU-2018-2274-1212084Fixed
neomuttsisyphus20180716-alt120240329-alt1ALT-PU-2018-2247-1212074Fixed
neomuttp1020180716-alt120210205-alt2ALT-PU-2018-2247-1212074Fixed
neomuttp920180716-alt120210205-alt2ALT-PU-2018-2247-1212074Fixed
neomuttc10f120180716-alt120210205-alt2ALT-PU-2018-2247-1212074Fixed
neomuttc9f220180716-alt120200821-alt2ALT-PU-2018-2247-1212074Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://neomutt.org/2018/07/16/release
  • Release Notes
  • Vendor Advisory
https://gitlab.com/muttmua/mutt/commit/6aed28b40a0410ec47d40c8c7296d8d10bae7576
  • Patch
  • Third Party Advisory
https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e
  • Third Party Advisory
  • Patch
http://www.mutt.org/news.html
  • Release Notes
  • Vendor Advisory
[debian-lts-announce] 20180802 [SECURITY] [DLA 1455-1] mutt security update
  • Mailing List
  • Third Party Advisory
DSA-4277
  • Third Party Advisory
RHSA-2018:2526
  • Third Party Advisory
USN-3719-3
  • Third Party Advisory
GLSA-201810-07
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:*
      End excliding
      1.10.1

      cpe:2.3:a:neomutt:neomutt:*:*:*:*:*:*:*:*
      End excliding
      20180716

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.7:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*