CVE-2018-14360
published 2018-07-17CVE-2018-14360: An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.65%
83.9th percentile
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mutt | < mutt 1.9.1-1 (bookworm) | mutt 1.9.1-1 (bookworm) |
| debian | neomutt | < mutt 1.9.1-1 (bookworm) | mutt 1.9.1-1 (bookworm) |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| neomutt | neomutt | < 20180716 | 20180716 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20171215+dfsg.1-1ubuntu0.1~esm1 | 20171215+dfsg.1-1ubuntu0.1~esm1 |
| neomutt | neomutt | >= 0 < 20191207+dfsg.1-1.1ubuntu0.1~esm1 | 20191207+dfsg.1-1.1ubuntu0.1~esm1 |
| neomutt | neomutt | >= 0 < 20211029+dfsg1-1ubuntu0.1~esm1 | 20211029+dfsg1-1ubuntu0.1~esm1 |
| neomutt | neomutt | >= 0 < 20231103+dfsg1-1ubuntu0.1~esm1 | 20231103+dfsg1-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
neomutt vulnerabilities
osv·2025-01-15·CVSS 9.8
CVE-2018-14349 [CRITICAL] neomutt vulnerabilities
neomutt vulnerabilities
Jeriko One discovered that NeoMutt incorrectly handled certain IMAP
and POP3 responses. An attacker could possibly use this issue to
cause NeoMutt to crash, resulting in a denial of service, or
the execution of arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-14349, CVE-2018-14350, CVE-2018-14351,
CVE-2018-14352, CVE-2018-14353, CVE-2018-14354, CVE-2018-14355,
CVE-2018-14356, CVE-2018-14357, CVE-2018-14358, CVE-2018-14359,
CVE-2018-14362)
Jeriko One discovered that NeoMutt incorrectly handled certain
NNTP-related operations. An attacker could possibly use this issue
to cause NeoMutt to crash, resulting in denial of service, or
the execution of arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-14360, CVE-2018-14361, CVE-2018-1
GHSA
GHSA-96qw-wpf6-h6f5: An issue was discovered in NeoMutt before 2018-07-16
ghsa_unreviewed·2022-05-13
CVE-2018-14360 [CRITICAL] CWE-787 GHSA-96qw-wpf6-h6f5: An issue was discovered in NeoMutt before 2018-07-16
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
OSV
CVE-2018-14360: An issue was discovered in NeoMutt before 2018-07-16
osv·2018-07-17·CVSS 9.8
CVE-2018-14360 [CRITICAL] CVE-2018-14360: An issue was discovered in NeoMutt before 2018-07-16
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
Ubuntu
NeoMutt vulnerabilities
vendor_ubuntu·2025-01-15·CVSS 9.8
CVE-2018-14361 [CRITICAL] NeoMutt vulnerabilities
Title: NeoMutt vulnerabilities
Summary: Several security issues were fixed in NeoMutt.
Jeriko One discovered that NeoMutt incorrectly handled certain IMAP
and POP3 responses. An attacker could possibly use this issue to
cause NeoMutt to crash, resulting in a denial of service, or
the execution of arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-14349, CVE-2018-14350, CVE-2018-14351,
CVE-2018-14352, CVE-2018-14353, CVE-2018-14354, CVE-2018-14355,
CVE-2018-14356, CVE-2018-14357, CVE-2018-14358, CVE-2018-14359,
CVE-2018-14362)
Jeriko One discovered that NeoMutt incorrectly handled certain
NNTP-related operations. An attacker could possibly use this issue
to cause NeoMutt to crash, resulting in denial of service, or
the execution of arbitrary code. This issue only affect
Debian
CVE-2018-14360: mutt - An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c...
vendor_debian·2018·CVSS 9.8
CVE-2018-14360 [CRITICAL] CVE-2018-14360: mutt - An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c...
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
Scope: local
bookworm: resolved (fixed in 1.9.1-1)
bullseye: resolved (fixed in 1.9.1-1)
forky: resolved (fixed in 1.9.1-1)
sid: resolved (fixed in 1.9.1-1)
trixie: resolved (fixed in 1.9.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/neomutt/neomutt/commit/6296f7153f0c9d5e5cd3aaf08f9731e56621bdd3https://lists.debian.org/debian-lts-announce/2018/08/msg00001.htmlhttps://neomutt.org/2018/07/16/releasehttps://www.debian.org/security/2018/dsa-4277https://github.com/neomutt/neomutt/commit/6296f7153f0c9d5e5cd3aaf08f9731e56621bdd3https://lists.debian.org/debian-lts-announce/2018/08/msg00001.htmlhttps://neomutt.org/2018/07/16/releasehttps://www.debian.org/security/2018/dsa-4277
2018-07-17
Published