PT-2018-3305 · Neomutt+4 · Neomutt+4

Jeriko-One

·

Published

2018-07-07

·

Updated

2025-01-15

·

CVE-2018-14360

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NeoMutt versions prior to 2018-07-16
Description The issue is related to a stack-based buffer overflow in the nntp add group function in the newsrc.c file of the NeoMutt email client. This overflow is caused by incorrect usage of the sscanf function, which can lead to errors in memory object handling. The exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For NeoMutt versions prior to 2018-07-16, update to a version released after 2018-07-16 to resolve the issue. As a temporary workaround, consider restricting access to the nntp add group function in the newsrc.c file until a patch is available. Avoid using the sscanf function in the affected nntp add group function until the issue is resolved.

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2247
ALT-PU-2018-2274
BDU:2019-04579
CVE-2018-14360
DLA-1455-1
DSA-4277-1
MGASA-2018-0447
OPENSUSE-SU-2018_2212-1
OPENSUSE-SU-2019_0052-1
OPENSUSE-SU-2024:11069-1
OPENSUSE-SU-2024:11079-1
SUSE-SU-2018:2084-1
SUSE-SU-2018:2085-1
SUSE-SU-2019:1196-1
USN-7204-1

Affected Products

Alt Linux
Linuxmint
Neomutt
Suse
Ubuntu