PT-2018-3305 · Neomutt+4 · Neomutt+4

Jeriko-One

·

Publicado

2018-07-07

·

Atualizado

2025-01-15

·

CVE-2018-14360

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NeoMutt versions prior to 2018-07-16
Description The issue is related to a stack-based buffer overflow in the nntp add group function in the newsrc.c file of the NeoMutt email client. This overflow is caused by incorrect usage of the sscanf function, which can lead to errors in memory object handling. The exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For NeoMutt versions prior to 2018-07-16, update to a version released after 2018-07-16 to resolve the issue. As a temporary workaround, consider restricting access to the nntp add group function in the newsrc.c file until a patch is available. Avoid using the sscanf function in the affected nntp add group function until the issue is resolved.

Correção

Memory Corruption

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2247
ALT-PU-2018-2274
BDU:2019-04579
CVE-2018-14360
DLA-1455-1
DSA-4277-1
MGASA-2018-0447
OPENSUSE-SU-2018_2212-1
OPENSUSE-SU-2019_0052-1
OPENSUSE-SU-2024:11069-1
OPENSUSE-SU-2024:11079-1
SUSE-SU-2018:2084-1
SUSE-SU-2018:2085-1
SUSE-SU-2019:1196-1
USN-7204-1

Produtos afetados

Alt Linux
Linuxmint
Neomutt
Suse
Ubuntu