PT-2014-8835 · Mutt+2 · Mutt+2

Published

2014-12-02

·

Updated

2024-06-15

·

CVE-2014-9116

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions mutt version 1.5.23
Description The issue is related to the improper handling of newline characters at the beginning of a header by the write one header function, which can be exploited by remote attackers to cause a denial of service (crash) via a header with an empty body. This triggers a heap-based buffer overflow in the mutt substrdup function.
Recommendations For mutt version 1.5.23, consider applying a patch or fix that properly handles newline characters at the beginning of a header to prevent the heap-based buffer overflow in the mutt substrdup function. As a temporary workaround, restrict the processing of headers with empty bodies to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9116
DLA-100-1
DSA-3083-1
MGASA-2014-0509
OPENSUSE-SU-2018_2212-1
OPENSUSE-SU-2019_0052-1
OPENSUSE-SU-2024:10198-1
SUSE-SU-2015:0758-1
SUSE-SU-2015_0012-1
SUSE-SU-2015_0758-1
SUSE-SU-2018:2084-1
SUSE-SU-2018:2085-1
SUSE-SU-2018_2084-1
SUSE-SU-2018_2085-1
SUSE-SU-2019:1196-1
SUSE-SU-2019_1196-1
USN-2440-1

Affected Products

Suse
Ubuntu
Mutt