CVE-2023-4874: Undefined Behavior for Input to API in Mutt
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/muttto a version that resolves this vulnerability.Fixed in 1.10.1-2.1+deb10u7Fixed in 2.0.5-4.1+deb11u3Fixed in 2.2.12-0.1~deb12u1Fixed in 2.2.9-1+deb12u1Fixed in 2.2.12-0.1 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.2.12-0.1 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 1.9.4-3ubuntu0.6+ - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 1.13.2-1ubuntu0.6 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.1.4-1ubuntu1.2 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.2.9-1ubuntu0.23.04.1 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 1.5.24-1ubuntu0.6+ - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.2.9-1ubuntu0.23.10.1 - Upgrade
Upgrade
debian/muttto a version that resolves this vulnerability.Fixed in 2.2.9-1+deb12u1Fixed in 2.2.12-0.1Fixed in 2.0.5-4.1+deb11u3 - Upgrade
Upgrade
redhat/muttto a version that resolves this vulnerability.Fixed in 2.2.12 - Upgrade
Upgrade
muttto a version that resolves this vulnerability.Fixed in 2.2.12
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4874.
What is the title of the vulnerability?
The title of the vulnerability is 'Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12'.
What is the severity of CVE-2023-4874?
The severity of CVE-2023-4874 is medium, with a severity value of 6.5.
How does CVE-2023-4874 affect Mutt?
CVE-2023-4874 affects Mutt versions >1.5.2 and <2.2.12.
How do I fix CVE-2023-4874?
To fix CVE-2023-4874, update Mutt to version 2.2.12 or later.