CVE-2023-4875: Undefined Behavior for Input to API in Mutt
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/muttto a version that resolves this vulnerability.Fixed in 1.10.1-2.1+deb10u7Fixed in 2.0.5-4.1+deb11u3Fixed in 2.2.12-0.1~deb12u1Fixed in 2.2.9-1+deb12u1Fixed in 2.2.12-0.1 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.2.12-0.1 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 1.9.4-3ubuntu0.6+ - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 1.13.2-1ubuntu0.6 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.1.4-1ubuntu1.2 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.2.9-1ubuntu0.23.04.1 - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 1.5.24-1ubuntu0.6+ - Upgrade
Upgrade
ubuntu/muttto a version that resolves this vulnerability.Fixed in 2.2.9-1ubuntu0.23.10.1 - Upgrade
Upgrade
redhat/muttto a version that resolves this vulnerability.Fixed in 2.2.12 - Upgrade
Upgrade
muttmua/muttto a version that resolves this vulnerability.Fixed in 2.2.12 - Compensating control
Do not compose messages (including drafts) originating from specially crafted draft messages until the Mutt upgrade to 2.2.12 is applied.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4875.
What is the title of the vulnerability?
The title of the vulnerability is 'Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12'.
What is the severity rating of CVE-2023-4875?
CVE-2023-4875 has a severity rating of medium with a value of 5.7.
How can I fix the CVE-2023-4875 vulnerability?
To fix the CVE-2023-4875 vulnerability, update Mutt to version 1.5.24-1ubuntu0.6+ or later.
Where can I find more information about CVE-2023-4875?
More information about CVE-2023-4875 can be found at the following references: [1](https://gitlab.com/muttmua/mutt/-/commit/452ee330e094bfc7c9a68555e5152b1826534555), [2](https://gitlab.com/muttmua/mutt/-/commit/4cc3128abdf52c615911589394a03271fddeefc6), [3](http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20230904/000056.html).