Logo
componentmutt
Name
mutt
Version
2.1.5-r2
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:mutt:mutt:2.1.5:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
2.1.5-r2

Vulnerabilities#


Name
Analysis
Description
Exploitable
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
Exploitable
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
Exploitable
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
Exploitable
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
Exploitable
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
Exploitable
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
Exploitable
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
Exploitable
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
Exploitable
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
Exploitable
Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.