CVE-2018-14357: OS Command Injection
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-14357.
What is the severity of CVE-2018-14357?
CVE-2018-14357 has a severity level of critical.
Which software versions are affected by CVE-2018-14357?
Mutt versions before 1.10.1 and NeoMutt versions before 2018-07-16 are affected.
How can remote IMAP servers execute arbitrary commands through CVE-2018-14357?
Remote IMAP servers can execute arbitrary commands through the backquote characters in the mailboxes command associated with an automatic subscription.
Where can I find more information about CVE-2018-14357?
More information about CVE-2018-14357 can be found at the following references: [http://www.mutt.org/news.html](http://www.mutt.org/news.html), [https://gitlab.com/muttmua/mutt/commit/185152818541f5cdc059cbff3f3e8b654fc27c1d](https://gitlab.com/muttmua/mutt/commit/185152818541f5cdc059cbff3f3e8b654fc27c1d), [https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725](https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725).