PT-2018-3300 · Mutt+7 · Mutt+7
Jeriko One
·
Published
2018-07-07
·
Updated
2025-01-15
·
CVE-2018-14354
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mutt versions prior to 1.10.1
NeoMutt versions prior to 2018-07-16
Description
The issue allows remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription. This is due to a lack of data sanitization at the management level, which can be exploited by a remote attacker to execute arbitrary commands.
Recommendations
For Mutt versions prior to 1.10.1, update to version 1.10.1 or later to resolve the issue.
For NeoMutt versions prior to 2018-07-16, update to a version released after 2018-07-16 to resolve the issue.
As a temporary workaround, consider restricting access to the mailboxes command associated with manual subscription or unsubscription to minimize the risk of exploitation.
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Linuxmint
Mutt
Neomutt
Red Hat
Suse
Ubuntu