HIGH
security flaw
Published Jun 27, 2006
7.5
HIGHCVSS 2.0
EPSS 6.00%
Description
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
mutt-5:1.4.1-3.5.rhel3
Fixed · RHSA-2006:0577
Red Hat Enterprise Linux 4
mutt-5:1.4.1-11.rhel4
Fixed · RHSA-2006:0577
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | mutt-5:1.4.1-3.5.rhel3 | Fixed | RHSA-2006:0577 |
| Red Hat Enterprise Linux 4 | mutt-5:1.4.1-11.rhel4 | Fixed | RHSA-2006:0577 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (34)
- ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U vendor-advisoryx_refsource_SGI
- http://dev.mutt.org/cgi-bin/gitweb.cgi?p=mutt/.git%3Ba=commit%3Bh=dc0272b749f0e2b102973b7ac43dbd3908507540 x_refsource_CONFIRM
- http://dev.mutt.org/cgi-bin/viewcvs.cgi/mutt/imap/browse.c?r1=1.34.2.2&r2=1.34.2.3 x_refsource_CONFIRM
- http://secunia.com/advisories/20810 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20836 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20854 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20879 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20887 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20895 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20960 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21039 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21124 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21135 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21220 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1016482 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472221 vendor-advisoryx_refsource_SLACKWARE
- http://www.debian.org/security/2006/dsa-1108 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200606-27.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:115 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_16_sr.html vendor-advisoryx_refsource_SUSE
- http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.013-mutt.html vendor-advisoryx_refsource_OPENPKG
- http://www.redhat.com/support/errata/RHSA-2006-0577.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/438712/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/18642 vdb-entryx_refsource_BID
- http://www.trustix.org/errata/2006/0038 vendor-advisoryx_refsource_TRUSTIX
- http://www.vupen.com/english/advisories/2006/2522 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-3242 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618137 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27428 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-471 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-3242
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10826 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/307-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-3242
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 27, 2006
Updated Aug 7, 2024
Reserved Jun 26, 2006
Link CVE-2006-3242
CISA Vulnrichment
Updated n/a