First published: Tue May 15 2007(Updated: )
Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mutt | =1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2683 has a moderate severity due to the potential for local users to execute arbitrary code.
To fix CVE-2007-2683, upgrade Mutt to version 1.5.17 or later.
Local users of Mutt version 1.4.2 are affected by CVE-2007-2683.
CVE-2007-2683 is a buffer overflow vulnerability.
CVE-2007-2683 can be exploited via crafted input using "&" characters in the GECOS field during alias expansion.