FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mutt/neomutt -- multiple vulnerabilities

Affected packages
neomutt < 20180716
mutt < 1.10.1
mutt14 < *

Details

VuXML ID fe12ef83-8b47-11e8-96cc-001a4a7ec6be
Discovery 2018-07-10
Entry 2018-07-19

NeoMutt report:

Description

CVE-2018-14349

NO Response Heap Overflow

CVE-2018-14350

INTERNALDATE Stack Overflow

CVE-2018-14351

STATUS Literal Length relative write

CVE-2018-14352

imap_quote_string off-by-one stack overflow

CVE-2018-14353

imap_quote_string int underflow

CVE-2018-14354

imap_subscribe Remote Code Execution

CVE-2018-14355

STATUS mailbox header cache directory traversal

CVE-2018-14356

POP empty UID NULL deref

CVE-2018-14357

LSUB Remote Code Execution

CVE-2018-14358

RFC822.SIZE Stack Overflow

CVE-2018-14359

base64 decode Stack Overflow

CVE-2018-14360

NNTP Group Stack Overflow

CVE-2018-14361

NNTP Write 1 where via GROUP response

CVE-2018-14362

POP Message Cache Directory Traversal

CVE-2018-14363

NNTP Header Cache Directory Traversal

References

CVE Name CVE-2018-14349
CVE Name CVE-2018-14350
CVE Name CVE-2018-14351
CVE Name CVE-2018-14352
CVE Name CVE-2018-14353
CVE Name CVE-2018-14354
CVE Name CVE-2018-14355
CVE Name CVE-2018-14356
CVE Name CVE-2018-14357
CVE Name CVE-2018-14358
CVE Name CVE-2018-14359
CVE Name CVE-2018-14360
CVE Name CVE-2018-14361
CVE Name CVE-2018-14362
CVE Name CVE-2018-14363
URL https://github.com/neomutt/neomutt/releases/tag/neomutt-20180716