cbcvebase.
CVE-2018-14357
published 2018-07-17

CVE-2018-14357: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.95%
91.2th percentile
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianmutt< mutt 1.10.1-1 (bookworm)mutt 1.10.1-1 (bookworm)
debianneomutt< mutt 1.10.1-1 (bookworm)mutt 1.10.1-1 (bookworm)
muttmutt< 1.10.11.10.1
muttmutt>= 0 < 1.10.1-11.10.1-1
muttmutt>= 0 < 1.10.1-11.10.1-1
muttmutt>= 0 < 1.10.1-11.10.1-1
muttmutt>= 0 < 1.10.1-11.10.1-1
muttmutt>= 0 < 1.5.21-6.4ubuntu2.21.5.21-6.4ubuntu2.2
muttmutt>= 0 < 1.5.24-1ubuntu0.21.5.24-1ubuntu0.2
muttmutt>= 0 < 1.5.24-1ubuntu0.11.5.24-1ubuntu0.1
muttmutt>= 0 < 1.9.4-3ubuntu0.11.9.4-3ubuntu0.1
neomuttneomutt< 2018071620180716
neomuttneomutt>= 0 < 20180716+dfsg.1-120180716+dfsg.1-1
neomuttneomutt>= 0 < 20180716+dfsg.1-120180716+dfsg.1-1
neomuttneomutt>= 0 < 20180716+dfsg.1-120180716+dfsg.1-1
neomuttneomutt>= 0 < 20180716+dfsg.1-120180716+dfsg.1-1
neomuttneomutt>= 0 < 20171215+dfsg.1-1ubuntu0.1~esm120171215+dfsg.1-1ubuntu0.1~esm1
neomuttneomutt>= 0 < 20191207+dfsg.1-1.1ubuntu0.1~esm120191207+dfsg.1-1.1ubuntu0.1~esm1
neomuttneomutt>= 0 < 20211029+dfsg1-1ubuntu0.1~esm120211029+dfsg1-1ubuntu0.1~esm1
neomuttneomutt>= 0 < 20231103+dfsg1-1ubuntu0.1~esm120231103+dfsg1-1ubuntu0.1~esm1

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/muttmua/mutt/commit/185152818541f5cdc059cbff3f3e8b654fc27c1d
urlhttps://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725
commandbackquote characters in IMAP server-supplied mailbox names (mailboxes command)
  • Monitor for backquote/backtick characters (`) in IMAP server responses, particularly in mailbox names delivered during automatic subscription negotiation, which Mutt/NeoMutt may pass to a shell via the 'mailboxes' command.
  • ·Mutt versions before 1.10.1 and NeoMutt versions before 2018-07-16 are vulnerable. Patch or upgrade to fixed versions (Mutt >= 1.10.1, NeoMutt >= 2018-07-16) to remediate.
  • ·Red Hat Enterprise Linux 5 will not receive a fix for this CVE; RHEL 8 is not affected. RHEL 6 and 7 were addressed via RHSA-2018:2526.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.