PT-2014-1766 · Debian+4 · Mutt+4

Beatrice Torracca

+1

·

Published

2014-03-14

·

Updated

2024-06-15

·

CVE-2014-0467

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mutt versions prior to 1.5.23
Description The issue is related to multiple vulnerabilities in the Mutt package of the Debian GNU/Linux operating system, which can lead to disruption of protected information availability. These vulnerabilities can be exploited remotely. A buffer overflow in the copy.c file of Mutt before version 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Recommendations For versions prior to 1.5.23, update to version 1.5.23 or later to resolve the issue. As a temporary workaround, consider restricting access to the copy.c file or disabling the address expansion feature in Mutt until a patch is available. Avoid using crafted RFC2047 header lines in the affected Mutt versions to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1458
BDU:2015-01338
CESA-2014_0304
CVE-2014-0467
DSA-2874-1
MGASA-2014-0141
OPENSUSE-SU-2024:10198-1
RHSA-2014:0304
RHSA-2014_0304
SUSE-SU-2014_0471-1
SUSE-SU-2015:0758-1

Affected Products

Alt Linux
Centos
Mutt
Red Hat
Suse