Logo
componentmutt
Name
mutt
Version
2.2.16
Type
library
Description
-
Licenses
GPL-2.0+
PURL
-
CPE
cpe:2.3:a:mutt:mutt:2.2.16:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
2.3.2

Vulnerabilities#


Name
Analysis
Description
Exploitable
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
Exploitable
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
Exploitable
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
Exploitable
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
Exploitable
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
Exploitable
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
Exploitable
Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.