First published: Sat Mar 29 2003(Updated: )
Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mutt | =1.3.12.1 | |
Mutt | =1.3.27 | |
Mutt | =1.3.16 | |
Mutt | =1.3.25 | |
Mutt | =1.3.22 | |
Mutt | =1.3.28 | |
Mutt | =1.3.24 | |
Mutt | =1.3.17 | |
Mutt | =1.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0167 can lead to a denial of service and may allow remote code execution by exploiting buffer overflow vulnerabilities.
CVE-2003-0167 affects Mutt versions 1.3.12, 1.3.16, 1.3.17, 1.3.22, 1.3.24, 1.3.25, 1.3.27, and 1.3.28.
To mitigate CVE-2003-0167, consider upgrading to a patched version of Mutt that addresses these vulnerabilities.
Yes, CVE-2003-0167 is mentioned as a different vulnerability from other similar vulnerabilities affecting the same software.
If you are using an affected version, it is crucial to update your Mutt software to the latest stable release to avoid potential exploitation.