USN-6374-1: Mutt vulnerabilities
Published Sep 14, 2023
·Updated
It was discovered that Mutt incorrectly handled certain email header contents. If a user were tricked into opening a specially crafted message, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-4874, CVE-2023-4875)
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/mutt<2.2.9-1ubuntu0.23.04.1
2.2.9-1ubuntu0.23.04.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/mutt<2.1.4-1ubuntu1.2
2.1.4-1ubuntu1.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/mutt<1.13.2-1ubuntu0.6
1.13.2-1ubuntu0.6
Ubuntu Ubuntu=20.04
All of the following
ubuntu/mutt<1.9.4-3ubuntu0.6+esm1
1.9.4-3ubuntu0.6+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/mutt<1.5.24-1ubuntu0.6+esm3
1.5.24-1ubuntu0.6+esm3
Ubuntu Ubuntu=16.04
All of the following
ubuntu/mutt-patched<1.5.24-1ubuntu0.6+esm3
1.5.24-1ubuntu0.6+esm3
Ubuntu Ubuntu=16.04
Event History
Sep 14, 2023
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this advisory?
CVE-2023-4874, CVE-2023-4875
2
What is the affected software?
Mutt on Ubuntu 23.04, 22.04, 20.04, 18.04, and 16.04
3
How can a remote attacker exploit this vulnerability?
By tricking a user into opening a specially crafted email message
4
What is the severity of this vulnerability?
The severity of this vulnerability is not specified in the advisory.
5
How can I fix this vulnerability?
Apply the recommended updates for Mutt provided by Ubuntu.