Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-14362 Details

Description

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2018:2526 CVEThird Party Advisory
https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e CVEPatchThird Party Advisory
https://gitlab.com/muttmua/mutt/commit/6aed28b40a0410ec47d40c8c7296d8d10bae7576 CVEPatchThird Party Advisory
https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html CVEMailing ListThird Party Advisory
https://neomutt.org/2018/07/16/release CVERelease NotesVendor Advisory

see all 18 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer[email protected]

Affected Products

ProductVersions

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-14362
NVD Published Date:
Jul 17, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2018-14362 Details - Not Deferred