CVE-2018-14355: Path Traversal
Published Jul 17, 2018
·Updated
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
Affected Software
7 affected componentsFixes available
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Mutt Mutt<1.10.1
neomutt neomutt<20180716
Canonical Ubuntu Linux=16.04
debian/mutt
2.0.5-4.1+deb11u32.2.12-0.1~deb12u12.2.9-1+deb12u12.2.13-1
debian/neomutt
20201127+dfsg.1-1.220220429+dfsg1-4.120250510+dfsg-220260105+dfsg-1
Remediation
Event History
Jul 17, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:51 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:04 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:04 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
CVE-2018-14355
2
What is the severity of CVE-2018-14355?
The severity of CVE-2018-14355 is medium with a CVSS score of 5.3.
3
What software versions are affected by CVE-2018-14355?
Mutt versions before 1.10.1 and NeoMutt versions before 2018-07-16 are affected.
4
How does CVE-2018-14355 impact the software?
CVE-2018-14355 allows an attacker to perform directory traversal in a mailbox name.
5
How can I fix CVE-2018-14355?
To fix CVE-2018-14355, update Mutt to version 1.10.1 or later, or update NeoMutt to version 2018-07-16 or later.