PT-2018-3305 · Neomutt+4 · Neomutt+4
Jeriko-One
·
Published
2018-07-07
·
Updated
2025-01-15
·
CVE-2018-14360
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NeoMutt versions prior to 2018-07-16
Description
The issue is related to a stack-based buffer overflow in the nntp add group function in the newsrc.c file of the NeoMutt email client. This overflow is caused by incorrect usage of the
sscanf function, which can lead to errors in memory object handling. The exploitation of this issue may allow a remote attacker to execute arbitrary code.Recommendations
For NeoMutt versions prior to 2018-07-16, update to a version released after 2018-07-16 to resolve the issue. As a temporary workaround, consider restricting access to the
nntp add group function in the newsrc.c file until a patch is available. Avoid using the sscanf function in the affected nntp add group function until the issue is resolved.Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Neomutt
Suse
Ubuntu