CVE-2018-14351: Input Validation
Published Jul 17, 2018
·Updated
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
Affected Software
7 affected componentsFixes available
Mutt Mutt<1.10.1
neomutt neomutt<20180716
Canonical Ubuntu Linux=16.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/mutt
2.0.5-4.1+deb11u32.2.12-0.1~deb12u12.2.9-1+deb12u12.2.13-1
debian/neomutt
20201127+dfsg.1-1.220220429+dfsg1-4.120250404+dfsg-2
Remediation
Event History
Jul 17, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:51 PM
Description
Jan 18, 2025
Data Sourced
via Ubuntu·02:17 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2018-14351?
CVE-2018-14351 is a vulnerability discovered in Mutt and NeoMutt that mishandles a long IMAP status mailbox literal count size.
2
What is the severity of CVE-2018-14351?
The severity of CVE-2018-14351 is critical with a CVSS score of 9.8.
3
How does CVE-2018-14351 affect Mutt and NeoMutt?
CVE-2018-14351 affects Mutt versions before 1.10.1 and NeoMutt versions before 2018-07-16.
4
How can I fix CVE-2018-14351 in Mutt?
To fix CVE-2018-14351 in Mutt, update to version 1.10.1 or higher.
5
How can I fix CVE-2018-14351 in NeoMutt?
To fix CVE-2018-14351 in NeoMutt, update to version 2018-07-16 or higher.