CVE-2014-0467
mutt: heap-based buffer overflow when parsing certain headers
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
Desbordamiento de buffer en copy.c en Mutt anterior a 1.5.23 permite a atacantes remotos causar una denegación de servicio (caída) a través de una línea de cabecera RFC2047 manipulada, relacionado con la expansión de dirección.
Mutt is a text-mode mail user agent. A heap-based buffer overflow flaw was found in the way mutt processed certain email headers. A remote attacker could use this flaw to send an email with specially crafted headers that, when processed, could cause mutt to crash or, potentially, execute arbitrary code with the permissions of the user running mutt. All mutt users are advised to upgrade to this updated package, which contains a backported patch to correct this issue. All running instances of mutt must be restarted for this update to take effect.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-19 CVE Reserved
- 2014-03-12 CVE Published
- 2023-10-25 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-122: Heap-based Buffer Overflow
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.mutt.org/doc/devel/ChangeLog | X_refsource_confirm | |
http://www.securityfocus.com/bid/66165 | Vdb Entry | |
http://www.securitytracker.com/id/1029919 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | <= 1.5.22 Search vendor "Mutt" for product "Mutt" and version " <= 1.5.22" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5 Search vendor "Mutt" for product "Mutt" and version "1.5" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.1 Search vendor "Mutt" for product "Mutt" and version "1.5.1" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.2 Search vendor "Mutt" for product "Mutt" and version "1.5.2" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.3 Search vendor "Mutt" for product "Mutt" and version "1.5.3" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.4 Search vendor "Mutt" for product "Mutt" and version "1.5.4" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.5 Search vendor "Mutt" for product "Mutt" and version "1.5.5" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.6 Search vendor "Mutt" for product "Mutt" and version "1.5.6" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.7 Search vendor "Mutt" for product "Mutt" and version "1.5.7" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.8 Search vendor "Mutt" for product "Mutt" and version "1.5.8" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.9 Search vendor "Mutt" for product "Mutt" and version "1.5.9" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.10 Search vendor "Mutt" for product "Mutt" and version "1.5.10" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.11 Search vendor "Mutt" for product "Mutt" and version "1.5.11" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.12 Search vendor "Mutt" for product "Mutt" and version "1.5.12" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.13 Search vendor "Mutt" for product "Mutt" and version "1.5.13" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.14 Search vendor "Mutt" for product "Mutt" and version "1.5.14" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.15 Search vendor "Mutt" for product "Mutt" and version "1.5.15" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.16 Search vendor "Mutt" for product "Mutt" and version "1.5.16" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.17 Search vendor "Mutt" for product "Mutt" and version "1.5.17" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.18 Search vendor "Mutt" for product "Mutt" and version "1.5.18" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.19 Search vendor "Mutt" for product "Mutt" and version "1.5.19" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.20 Search vendor "Mutt" for product "Mutt" and version "1.5.20" | - |
Affected
| ||||||
Mutt Search vendor "Mutt" | Mutt Search vendor "Mutt" for product "Mutt" | 1.5.21 Search vendor "Mutt" for product "Mutt" and version "1.5.21" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 11.4 Search vendor "Opensuse" for product "Opensuse" and version "11.4" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 12.3 Search vendor "Opensuse" for product "Opensuse" and version "12.3" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.1 Search vendor "Opensuse" for product "Opensuse" and version "13.1" | - |
Affected
|