First published: Sat Sep 09 2023(Updated: )
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
Credit: cve@gitlab.com cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mutt | <=1.10.1-2.1+deb10u6 | 1.10.1-2.1+deb10u7 2.0.5-4.1+deb11u3 2.2.12-0.1~deb12u1 2.2.9-1+deb12u1 2.2.12-0.1 |
Mutt Mutt | >1.5.2<2.2.12 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
ubuntu/mutt | <2.2.12-0.1 | 2.2.12-0.1 |
ubuntu/mutt | <1.9.4-3ubuntu0.6+ | 1.9.4-3ubuntu0.6+ |
ubuntu/mutt | <1.13.2-1ubuntu0.6 | 1.13.2-1ubuntu0.6 |
ubuntu/mutt | <2.1.4-1ubuntu1.2 | 2.1.4-1ubuntu1.2 |
ubuntu/mutt | <2.2.9-1ubuntu0.23.04.1 | 2.2.9-1ubuntu0.23.04.1 |
ubuntu/mutt | <1.5.24-1ubuntu0.6+ | 1.5.24-1ubuntu0.6+ |
ubuntu/mutt | <2.2.9-1ubuntu0.23.10.1 | 2.2.9-1ubuntu0.23.10.1 |
redhat/mutt | <2.2.12 | 2.2.12 |
Upgrade to version 2.2.12
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4875.
The title of the vulnerability is 'Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12'.
CVE-2023-4875 has a severity rating of medium with a value of 5.7.
To fix the CVE-2023-4875 vulnerability, update Mutt to version 1.5.24-1ubuntu0.6+ or later.
More information about CVE-2023-4875 can be found at the following references: [1](https://gitlab.com/muttmua/mutt/-/commit/452ee330e094bfc7c9a68555e5152b1826534555), [2](https://gitlab.com/muttmua/mutt/-/commit/4cc3128abdf52c615911589394a03271fddeefc6), [3](http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20230904/000056.html).