cbcvebase.
CVE-2023-4875
published 2023-09-09

CVE-2023-4875: Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12

PriorityP425medium5.7CVSS 3.1
AVNACLPRLUIRSUCNINAH
EPSS
0.51%
39.8th percentile
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianmutt< mutt 2.2.9-1+deb12u1 (bookworm)mutt 2.2.9-1+deb12u1 (bookworm)
gitlabmutt
msrccbl2_mutt_2.2.12-1_on_cbl_mariner_2.0
muttmutt< 2.2.122.2.12
muttmutt>= 0 < 2.0.5-4.1+deb11u32.0.5-4.1+deb11u3
muttmutt>= 0 < 2.2.9-1+deb12u12.2.9-1+deb12u1
muttmutt>= 0 < 2.2.12-0.12.2.12-0.1
muttmutt>= 0 < 2.2.12-0.12.2.12-0.1
muttmutt>= 0 < 1.13.2-1ubuntu0.61.13.2-1ubuntu0.6
muttmutt>= 0 < 2.1.4-1ubuntu1.22.1.4-1ubuntu1.2
muttmutt>= 0 < 2.2.9-1ubuntu0.23.10.12.2.9-1ubuntu0.23.10.1
muttmutt>= 0 < 1.5.24-1ubuntu0.6+esm31.5.24-1ubuntu0.6+esm3
muttmutt>= 0 < 1.9.4-3ubuntu0.6+esm11.9.4-3ubuntu0.6+esm1
muttmutt>= 1.5.2 < 2.2.122.2.12

CVSS provenance

nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_msrc5.7MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian2.2LOW
vendor_redhat2.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.