A heap-based buffer overflow flaw was reported in the muttsubstrdup() function in Mutt. Opening a specially-crafted mail message could cause mutt to crash or, potentially, execute arbitrary code.
CVE request:
http://www.openwall.com/lists/oss-security/2014/11/27/5
In testing on Fedora, "set weed=no" had to be set in the user's .muttrc before the issue presented.