PT-2018-3300 · Mutt+7 · Mutt+7

Jeriko One

·

Published

2018-07-07

·

Updated

2025-01-15

·

CVE-2018-14354

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mutt versions prior to 1.10.1 NeoMutt versions prior to 2018-07-16
Description The issue allows remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription. This is due to a lack of data sanitization at the management level, which can be exploited by a remote attacker to execute arbitrary commands.
Recommendations For Mutt versions prior to 1.10.1, update to version 1.10.1 or later to resolve the issue. For NeoMutt versions prior to 2018-07-16, update to a version released after 2018-07-16 to resolve the issue. As a temporary workaround, consider restricting access to the mailboxes command associated with manual subscription or unsubscription to minimize the risk of exploitation.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2247
ALT-PU-2018-2274
BDU:2019-04574
CESA-2018_2526
CVE-2018-14354
DLA-1455-1
DSA-4277-1
MGASA-2018-0447
OPENSUSE-SU-2018_2212-1
OPENSUSE-SU-2019_0052-1
OPENSUSE-SU-2024:11069-1
OPENSUSE-SU-2024:11079-1
RHSA-2018:2526
RHSA-2018_2526
SUSE-SU-2018:2084-1
SUSE-SU-2018:2085-1
SUSE-SU-2018:2403-1
SUSE-SU-2019:1196-1
USN-3719-1
USN-3719-2
USN-3719-3
USN-7204-1

Affected Products

Alt Linux
Centos
Linuxmint
Mutt
Neomutt
Red Hat
Suse
Ubuntu