CVE-2014-9116
published 2014-12-02CVE-2014-9116: The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
9.69%
95.0th percentile
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mutt | < mutt 1.5.23-2 (bookworm) | mutt 1.5.23-2 (bookworm) |
| mageia | mageia | — | — |
| mutt | mutt | — | — |
| mutt | mutt | >= 0 < 1.5.23-2 | 1.5.23-2 |
| mutt | mutt | >= 0 < 1.5.23-2 | 1.5.23-2 |
| mutt | mutt | >= 0 < 1.5.23-2 | 1.5.23-2 |
| mutt | mutt | >= 0 < 1.5.23-2 | 1.5.23-2 |
| suse | linux_enterprise_desktop | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mutt vulnerability
vendor_ubuntu·2014-12-11
CVE-2014-9116 Mutt vulnerability
Title: Mutt vulnerability
Summary: The mutt mail client could be made to crash if it opened a specially
crafted email.
Jakub Wilk discovered that the write_one_header function in mutt
did not properly handle newline characters at the beginning of a
header. An attacker could specially craft an email to cause mutt to
crash, resulting in a denial of service.
Instructions: After a standard system update you need to restart any running
instances of mutt to make all the necessary changes.
Red Hat
mutt: incorrect use of mutt_substrdup() in write_one_header()
vendor_redhat·2014-11-26·CVSS 5.0
CVE-2014-9116 [MEDIUM] CWE-119 mutt: incorrect use of mutt_substrdup() in write_one_header()
mutt: incorrect use of mutt_substrdup() in write_one_header()
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
Package: mutt (Red Hat Enterprise Linux 5) - Not affected
Package: mutt (Red Hat Enterprise Linux 6) - Will not fix
Package: mutt (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9116: mutt - The write_one_header function in mutt 1.5.23 does not properly handle newline ch...
vendor_debian·2014·CVSS 5.0
CVE-2014-9116 [MEDIUM] CVE-2014-9116: mutt - The write_one_header function in mutt 1.5.23 does not properly handle newline ch...
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
Scope: local
bookworm: resolved (fixed in 1.5.23-2)
bullseye: resolved (fixed in 1.5.23-2)
forky: resolved (fixed in 1.5.23-2)
sid: resolved (fixed in 1.5.23-2)
trixie: resolved (fixed in 1.5.23-2)
GHSA
GHSA-mv99-5p2c-93vv: The write_one_header function in mutt 1
ghsa_unreviewed·2022-05-14
CVE-2014-9116 [MEDIUM] CWE-119 GHSA-mv99-5p2c-93vv: The write_one_header function in mutt 1
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
OSV
CVE-2014-9116: The write_one_header function in mutt 1
osv·2014-12-02·CVSS 5.0
CVE-2014-9116 [MEDIUM] CVE-2014-9116: The write_one_header function in mutt 1
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0509.htmlhttp://dev.mutt.org/trac/ticket/3716http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00002.htmlhttp://www.debian.org/security/2014/dsa-3083http://www.mandriva.com/security/advisories?name=MDVSA-2014:245http://www.mandriva.com/security/advisories?name=MDVSA-2015:078http://www.openwall.com/lists/oss-security/2014/11/27/5http://www.openwall.com/lists/oss-security/2014/11/27/9http://www.securityfocus.com/bid/71334http://www.securitytracker.com/id/1031266https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771125https://bugzilla.redhat.com/show_bug.cgi?id=1168463https://security.gentoo.org/glsa/201701-04http://advisories.mageia.org/MGASA-2014-0509.htmlhttp://dev.mutt.org/trac/ticket/3716http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00002.htmlhttp://www.debian.org/security/2014/dsa-3083http://www.mandriva.com/security/advisories?name=MDVSA-2014:245http://www.mandriva.com/security/advisories?name=MDVSA-2015:078http://www.openwall.com/lists/oss-security/2014/11/27/5http://www.openwall.com/lists/oss-security/2014/11/27/9http://www.securityfocus.com/bid/71334http://www.securitytracker.com/id/1031266https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771125https://bugzilla.redhat.com/show_bug.cgi?id=1168463https://security.gentoo.org/glsa/201701-04
2014-12-02
Published