CVE-2006-3242
published 2006-06-27CVE-2006-3242: Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.89%
92.4th percentile
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mutt | < mutt 1.5.11+cvs20060403-2 (bookworm) | mutt 1.5.11+cvs20060403-2 (bookworm) |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | >= 0 < 1.5.11+cvs20060403-2 | 1.5.11+cvs20060403-2 |
| mutt | mutt | >= 0 < 1.5.11+cvs20060403-2 | 1.5.11+cvs20060403-2 |
| mutt | mutt | >= 0 < 1.5.11+cvs20060403-2 | 1.5.11+cvs20060403-2 |
| mutt | mutt | >= 0 < 1.5.11+cvs20060403-2 | 1.5.11+cvs20060403-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2006-06-19·CVSS 7.5
CVE-2006-3242 [HIGH] security flaw
security flaw
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.
Debian
CVE-2006-3242: mutt - Stack-based buffer overflow in the browse_get_namespace function in imap/browse....
vendor_debian·2006·CVSS 7.5
CVE-2006-3242 [HIGH] CVE-2006-3242: mutt - Stack-based buffer overflow in the browse_get_namespace function in imap/browse....
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.
Scope: local
bookworm: resolved (fixed in 1.5.11+cvs20060403-2)
bullseye: resolved (fixed in 1.5.11+cvs20060403-2)
forky: resolved (fixed in 1.5.11+cvs20060403-2)
sid: resolved (fixed in 1.5.11+cvs20060403-2)
trixie: resolved (fixed in 1.5.11+cvs20060403-2)
GHSA
GHSA-pg87-fxp9-w848: Stack-based buffer overflow in the browse_get_namespace function in imap/browse
ghsa_unreviewed·2022-05-03
CVE-2006-3242 [HIGH] GHSA-pg87-fxp9-w848: Stack-based buffer overflow in the browse_get_namespace function in imap/browse
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.
OSV
CVE-2006-3242: Stack-based buffer overflow in the browse_get_namespace function in imap/browse
osv·2006-06-27·CVSS 7.5
CVE-2006-3242 [HIGH] CVE-2006-3242: Stack-based buffer overflow in the browse_get_namespace function in imap/browse
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3242 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-3242 [HIGH] CVE-2006-3242 security flaw
CVE-2006-3242 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.
Bugzilla
CVE-2006-3242 Mutt IMAP namespace buffer overflow
bugzilla·2006-06-28·CVSS 7.5
CVE-2006-3242 [HIGH] CVE-2006-3242 Mutt IMAP namespace buffer overflow
CVE-2006-3242 Mutt IMAP namespace buffer overflow
Mutt IMAP namespace buffer overflow
A buffer overflow flaw was found in the way mutt processes an overly
long namespace from a malicious imap server. In order to exploit this
flaw a user would have to connect to a malicious IMAP server.
http://secunia.com/advisories/20810
Discussion:
mutt-1.4.2.1-5.fc4 has been pushed for fc4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
Bugzilla
CVE-2006-3242 Mutt IMAP namespace buffer overflow
bugzilla·2006-06-28·CVSS 7.5
CVE-2006-3242 [HIGH] CVE-2006-3242 Mutt IMAP namespace buffer overflow
CVE-2006-3242 Mutt IMAP namespace buffer overflow
Mutt IMAP namespace buffer overflow
A buffer overflow flaw was found in the way mutt processes an overly
long namespace from a malicious imap server. In order to exploit this
flaw a user would have to connect to a malicious IMAP server.
http://secunia.com/advisories/20810
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0577.html
ftp://patches.sgi.com/support/free/security/advisories/20060701-01-Uhttp://dev.mutt.org/cgi-bin/gitweb.cgi?p=mutt/.git%3Ba=commit%3Bh=dc0272b749f0e2b102973b7ac43dbd3908507540http://dev.mutt.org/cgi-bin/viewcvs.cgi/mutt/imap/browse.c?r1=1.34.2.2&r2=1.34.2.3http://secunia.com/advisories/20810http://secunia.com/advisories/20836http://secunia.com/advisories/20854http://secunia.com/advisories/20879http://secunia.com/advisories/20887http://secunia.com/advisories/20895http://secunia.com/advisories/20960http://secunia.com/advisories/21039http://secunia.com/advisories/21124http://secunia.com/advisories/21135http://secunia.com/advisories/21220http://securitytracker.com/id?1016482http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472221http://www.debian.org/security/2006/dsa-1108http://www.gentoo.org/security/en/glsa/glsa-200606-27.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:115http://www.novell.com/linux/security/advisories/2006_16_sr.htmlhttp://www.openpkg.org/security/advisories/OpenPKG-SA-2006.013-mutt.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0577.htmlhttp://www.securityfocus.com/archive/1/438712/100/0/threadedhttp://www.securityfocus.com/bid/18642http://www.trustix.org/errata/2006/0038http://www.vupen.com/english/advisories/2006/2522https://exchange.xforce.ibmcloud.com/vulnerabilities/27428https://issues.rpath.com/browse/RPL-471https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10826https://usn.ubuntu.com/307-1/ftp://patches.sgi.com/support/free/security/advisories/20060701-01-Uhttp://dev.mutt.org/cgi-bin/gitweb.cgi?p=mutt/.git%3Ba=commit%3Bh=dc0272b749f0e2b102973b7ac43dbd3908507540http://dev.mutt.org/cgi-bin/viewcvs.cgi/mutt/imap/browse.c?r1=1.34.2.2&r2=1.34.2.3http://secunia.com/advisories/20810http://secunia.com/advisories/20836http://secunia.com/advisories/20854http://secunia.com/advisories/20879http://secunia.com/advisories/20887http://secunia.com/advisories/20895http://secunia.com/advisories/20960http://secunia.com/advisories/21039http://secunia.com/advisories/21124http://secunia.com/advisories/21135http://secunia.com/advisories/21220http://securitytracker.com/id?1016482http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472221http://www.debian.org/security/2006/dsa-1108http://www.gentoo.org/security/en/glsa/glsa-200606-27.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:115http://www.novell.com/linux/security/advisories/2006_16_sr.htmlhttp://www.openpkg.org/security/advisories/OpenPKG-SA-2006.013-mutt.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0577.htmlhttp://www.securityfocus.com/archive/1/438712/100/0/threadedhttp://www.securityfocus.com/bid/18642http://www.trustix.org/errata/2006/0038http://www.vupen.com/english/advisories/2006/2522https://exchange.xforce.ibmcloud.com/vulnerabilities/27428https://issues.rpath.com/browse/RPL-471https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10826https://usn.ubuntu.com/307-1/
2006-06-27
Published