CVE-2014-0467: Buffer Overflow
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/muttto a version that resolves this vulnerability.Fixed in 2.0.5-4.1+deb11u3Fixed in 2.2.12-0.1~deb12u1Fixed in 2.2.9-1+deb12u1Fixed in 2.2.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0467?
CVE-2014-0467 has been classified as a denial of service vulnerability due to a buffer overflow issue.
How do I fix CVE-2014-0467?
To fix CVE-2014-0467, upgrade your Mutt installation to version 1.5.23 or later.
Which versions of Mutt are affected by CVE-2014-0467?
Versions of Mutt prior to 1.5.23, including all versions up to and including 1.5.22, are affected by CVE-2014-0467.
Can CVE-2014-0467 be exploited remotely?
Yes, CVE-2014-0467 can be exploited remotely through crafted RFC2047 header lines.
What are the potential consequences of CVE-2014-0467?
The potential consequences of CVE-2014-0467 include application crashes and denial of service for users of affected Mutt versions.