CVE-2018-14361: Input Validation
Published Jul 17, 2018
·Updated
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
Affected Software
5 affected componentsFixes available
Debian Debian Linux=8.0
Debian Debian Linux=9.0
neomutt neomutt<20180716
debian/mutt
2.0.5-4.1+deb11u32.2.12-0.1~deb12u12.2.9-1+deb12u12.2.13-1
debian/neomutt
20201127+dfsg.1-1.220220429+dfsg1-4.120250404+dfsg-2
Remediation
Event History
Jul 17, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 15, 2025
Data Sourced
via Launchpad·05:07 PM
Description
Jan 19, 2025
Data Sourced
via Ubuntu·05:07 PM
RemedyDescriptionSeverityAffected Software
May 13, 2025
Data Sourced
via Debian·12:15 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-14361?
The severity of CVE-2018-14361 is critical with a CVSS score of 9.8.
2
What is the affected software of CVE-2018-14361?
The affected software of CVE-2018-14361 includes NeoMutt versions up to and including 20180716.
3
How do I fix CVE-2018-14361 on Debian Linux 8.0?
To fix CVE-2018-14361 on Debian Linux 8.0, update the 'mutt' package to version 1.10.1-2.1+deb10u6 or later.
4
How do I fix CVE-2018-14361 on Debian Linux 9.0?
To fix CVE-2018-14361 on Debian Linux 9.0, update the 'mutt' package to version 1.10.1-2.1+deb10u7 or later.
5
How do I fix CVE-2018-14361 on NeoMutt?
To fix CVE-2018-14361 on NeoMutt, update to a version later than 20180716.