CVE-2006-3242Improper Restriction of Operations within the Bounds of a Memory Buffer in Mutt

8 documents6 sources
Severity
7.5HIGHNVD
EPSS
7.5%
top 8.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 27
Latest updateMay 3

Description

Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/mutt< mutt 1.5.11+cvs20060403-2 (bookworm)
Debianmutt/mutt< 1.5.11+cvs20060403-2+3
NVDmutt/mutt1.4.2, 1.4.2.1+1

🔴Vulnerability Details

2
GHSA
GHSA-pg87-fxp9-w848: Stack-based buffer overflow in the browse_get_namespace function in imap/browse2022-05-03
OSV
CVE-2006-3242: Stack-based buffer overflow in the browse_get_namespace function in imap/browse2006-06-27

📋Vendor Advisories

2
Red Hat
security flaw2006-06-19
Debian
CVE-2006-3242: mutt - Stack-based buffer overflow in the browse_get_namespace function in imap/browse....2006

💬Community

3
Bugzilla
CVE-2006-3242 security flaw2018-08-16
Bugzilla
CVE-2006-3242 Mutt IMAP namespace buffer overflow2006-06-28
Bugzilla
CVE-2006-3242 Mutt IMAP namespace buffer overflow2006-06-28