CVE-2003-0167: Buffer Overflow
Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What are the risks associated with CVE-2003-0167?
CVE-2003-0167 can lead to a denial of service and may allow remote code execution by exploiting buffer overflow vulnerabilities.
Which versions of Mutt are affected by CVE-2003-0167?
CVE-2003-0167 affects Mutt versions 1.3.12, 1.3.16, 1.3.17, 1.3.22, 1.3.24, 1.3.25, 1.3.27, and 1.3.28.
How can I mitigate the vulnerabilities identified in CVE-2003-0167?
To mitigate CVE-2003-0167, consider upgrading to a patched version of Mutt that addresses these vulnerabilities.
Is CVE-2003-0167 related to other vulnerabilities?
Yes, CVE-2003-0167 is mentioned as a different vulnerability from other similar vulnerabilities affecting the same software.
What should I do if I am using an affected version mentioned in CVE-2003-0167?
If you are using an affected version, it is crucial to update your Mutt software to the latest stable release to avoid potential exploitation.