CVE-2018-14358: Buffer Overflow
Published Jul 17, 2018
·Updated
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
Affected Software
9 affected componentsFixes available
Mutt Mutt<1.10.1
neomutt neomutt<20180716
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/mutt
2.0.5-4.1+deb11u32.2.12-0.1~deb12u12.2.9-1+deb12u12.2.13-1
debian/neomutt
20201127+dfsg.1-1.220220429+dfsg1-4.120250510+dfsg-220260105+dfsg-1
Remediation
Event History
Jul 17, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:51 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:04 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:04 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-14358?
CVE-2018-14358 is a vulnerability discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
2
What is the severity of CVE-2018-14358?
The severity of CVE-2018-14358 is critical, with a CVSS score of 9.8.
3
How does CVE-2018-14358 affect Mutt and NeoMutt?
CVE-2018-14358 leads to a stack-based buffer overflow in imap/message.c for a FETCH response with a long RFC822.SIZE field.
4
Which software versions are affected by CVE-2018-14358?
Mutt versions before 1.10.1 and NeoMutt versions before 2018-07-16 are affected by CVE-2018-14358.
5
Where can I find more information about CVE-2018-14358?
More information about CVE-2018-14358 can be found on the Mutt website and the NeoMutt GitHub and GitLab repositories.