CVE-2014-0467
published 2014-03-14CVE-2014-0467: Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.16%
91.5th percentile
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mutt | < mutt 1.5.22-2 (bookworm) | mutt 1.5.22-2 (bookworm) |
| mutt | mutt | <= 1.5.22 | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | — | — |
| mutt | mutt | >= 0 < 1.5.22-2 | 1.5.22-2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qw3h-r7wr-mxvx: Buffer overflow in copy
ghsa_unreviewed·2022-05-14
CVE-2014-0467 [MEDIUM] CWE-119 GHSA-qw3h-r7wr-mxvx: Buffer overflow in copy
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
OSV
CVE-2014-0467: Buffer overflow in copy
osv·2014-03-14·CVSS 5.0
CVE-2014-0467 [MEDIUM] CVE-2014-0467: Buffer overflow in copy
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Ubuntu
Mutt vulnerability
vendor_ubuntu·2014-03-13
CVE-2014-0467 Mutt vulnerability
Title: Mutt vulnerability
Summary: The mutt mail client could be made to crash or run programs as your
login if it opened a specially crafted email.
Beatrice Torracca and Evgeni Golov discovered a buffer overflow
in mutt while expanding addresses when parsing email headers. An
attacker could specially craft an email to cause mutt to crash,
resulting in a denial of service, or possibly execute arbitrary code
with the privileges of the user invoking mutt.
Instructions: After a standard system update you need to restart mutt to make
all the necessary changes.
Debian
CVE-2014-0467: mutt - Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause...
vendor_debian·2014·CVSS 5.0
CVE-2014-0467 [MEDIUM] CVE-2014-0467: mutt - Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause...
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Scope: local
bookworm: resolved (fixed in 1.5.22-2)
bullseye: resolved (fixed in 1.5.22-2)
forky: resolved (fixed in 1.5.22-2)
sid: resolved (fixed in 1.5.22-2)
trixie: resolved (fixed in 1.5.22-2)
Red Hat
mutt: heap-based buffer overflow when parsing certain headers
vendor_redhat·2013-05-18·CVSS 5.0
CVE-2014-0467 [MEDIUM] CWE-122 mutt: heap-based buffer overflow when parsing certain headers
mutt: heap-based buffer overflow when parsing certain headers
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Statement: This issue does not affect the version of mutt package as shipped with Red Hat Enterprise Linux 5.
Package: mutt (Red Hat Enterprise Linux 5) - Not affected
Package: mutt (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0467 mutt: heap-based buffer overflow when parsing certain headers [fedora-all]
bugzilla·2014-03-13·CVSS 5.0
CVE-2014-0467 [MEDIUM] CVE-2014-0467 mutt: heap-based buffer overflow when parsing certain headers [fedora-all]
CVE-2014-0467 mutt: heap-based buffer overflow when parsing certain headers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2014-0467 mutt: heap-based buffer overflow when parsing certain headers
bugzilla·2014-03-13·CVSS 5.0
CVE-2014-0467 [MEDIUM] CVE-2014-0467 mutt: heap-based buffer overflow when parsing certain headers
CVE-2014-0467 mutt: heap-based buffer overflow when parsing certain headers
The Debian DSA-2874-1 security advisory (http://www.debian.org/security/2014/dsa-2874) corrected an overflow in the mutt mail reader. Analysis of the crash reveals this is likely a heap-based buffer overflow in the mutt_copy_hdr() function. Opening a specially-crafted mail message could cause mutt to crash or, potentially, execute arbitrary code. The fix looks to be as follows:
+diff -r 3d5e23a66a1a -r 9bf7593e3c08 copy.c
+--- a/copy.c Thu Oct 24 09:55:36 2013 -0700
++++ b/copy.c Tue Mar 11 09:40:09 2014 -0700
+@@ -254,6 +254,7 @@
+ {
+ if (!address_header_decode (&this_one))
+ rfc2047_decode (&this_one);
++ this_one_len = mutt_strlen (this_one);
+ }
+
+ if (!headers[x])
+
(Note as this is copied from the Debian
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00083.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00085.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0304.htmlhttp://www.debian.org/security/2014/dsa-2874http://www.mutt.org/doc/devel/ChangeLoghttp://www.securityfocus.com/bid/66165http://www.securitytracker.com/id/1029919http://www.ubuntu.com/usn/USN-2147-1http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00083.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00085.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0304.htmlhttp://www.debian.org/security/2014/dsa-2874http://www.mutt.org/doc/devel/ChangeLoghttp://www.securityfocus.com/bid/66165http://www.securitytracker.com/id/1029919http://www.ubuntu.com/usn/USN-2147-1
2014-03-14
Published