CVE-2018-14363
published 2018-07-17CVE-2018-14363: An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.18%
80.2th percentile
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mutt | < mutt 1.9.1-1 (bookworm) | mutt 1.9.1-1 (bookworm) |
| debian | neomutt | < mutt 1.9.1-1 (bookworm) | mutt 1.9.1-1 (bookworm) |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| mutt | mutt | >= 0 < 1.9.1-1 | 1.9.1-1 |
| neomutt | neomutt | < 20180716 | 20180716 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20180716+dfsg.1-1 | 20180716+dfsg.1-1 |
| neomutt | neomutt | >= 0 < 20171215+dfsg.1-1ubuntu0.1~esm1 | 20171215+dfsg.1-1ubuntu0.1~esm1 |
| neomutt | neomutt | >= 0 < 20191207+dfsg.1-1.1ubuntu0.1~esm1 | 20191207+dfsg.1-1.1ubuntu0.1~esm1 |
| neomutt | neomutt | >= 0 < 20211029+dfsg1-1ubuntu0.1~esm1 | 20211029+dfsg1-1ubuntu0.1~esm1 |
| neomutt | neomutt | >= 0 < 20231103+dfsg1-1ubuntu0.1~esm1 | 20231103+dfsg1-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
neomutt vulnerabilities
osv·2025-01-15·CVSS 9.8
CVE-2018-14349 [CRITICAL] neomutt vulnerabilities
neomutt vulnerabilities
Jeriko One discovered that NeoMutt incorrectly handled certain IMAP
and POP3 responses. An attacker could possibly use this issue to
cause NeoMutt to crash, resulting in a denial of service, or
the execution of arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-14349, CVE-2018-14350, CVE-2018-14351,
CVE-2018-14352, CVE-2018-14353, CVE-2018-14354, CVE-2018-14355,
CVE-2018-14356, CVE-2018-14357, CVE-2018-14358, CVE-2018-14359,
CVE-2018-14362)
Jeriko One discovered that NeoMutt incorrectly handled certain
NNTP-related operations. An attacker could possibly use this issue
to cause NeoMutt to crash, resulting in denial of service, or
the execution of arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-14360, CVE-2018-14361, CVE-2018-1
GHSA
GHSA-jm86-h3mr-62qj: An issue was discovered in NeoMutt before 2018-07-16
ghsa_unreviewed·2022-05-13
CVE-2018-14363 [HIGH] CWE-22 GHSA-jm86-h3mr-62qj: An issue was discovered in NeoMutt before 2018-07-16
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
OSV
CVE-2018-14363: An issue was discovered in NeoMutt before 2018-07-16
osv·2018-07-17·CVSS 7.5
CVE-2018-14363 [HIGH] CVE-2018-14363: An issue was discovered in NeoMutt before 2018-07-16
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
Ubuntu
NeoMutt vulnerabilities
vendor_ubuntu·2025-01-15·CVSS 9.8
CVE-2018-14361 [CRITICAL] NeoMutt vulnerabilities
Title: NeoMutt vulnerabilities
Summary: Several security issues were fixed in NeoMutt.
Jeriko One discovered that NeoMutt incorrectly handled certain IMAP
and POP3 responses. An attacker could possibly use this issue to
cause NeoMutt to crash, resulting in a denial of service, or
the execution of arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-14349, CVE-2018-14350, CVE-2018-14351,
CVE-2018-14352, CVE-2018-14353, CVE-2018-14354, CVE-2018-14355,
CVE-2018-14356, CVE-2018-14357, CVE-2018-14358, CVE-2018-14359,
CVE-2018-14362)
Jeriko One discovered that NeoMutt incorrectly handled certain
NNTP-related operations. An attacker could possibly use this issue
to cause NeoMutt to crash, resulting in denial of service, or
the execution of arbitrary code. This issue only affect
Debian
CVE-2018-14363: mutt - An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly...
vendor_debian·2018·CVSS 7.5
CVE-2018-14363 [HIGH] CVE-2018-14363: mutt - An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly...
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
Scope: local
bookworm: resolved (fixed in 1.9.1-1)
bullseye: resolved (fixed in 1.9.1-1)
forky: resolved (fixed in 1.9.1-1)
sid: resolved (fixed in 1.9.1-1)
trixie: resolved (fixed in 1.9.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59ehttps://lists.debian.org/debian-lts-announce/2018/08/msg00001.htmlhttps://neomutt.org/2018/07/16/releasehttps://www.debian.org/security/2018/dsa-4277https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59ehttps://lists.debian.org/debian-lts-announce/2018/08/msg00001.htmlhttps://neomutt.org/2018/07/16/releasehttps://www.debian.org/security/2018/dsa-4277
2018-07-17
Published