Back

MEDIUM

mutt: incorrect use of mutt_substrdup() in write_one_header()

Published Dec 2, 2014

Description

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 2, 2014
Updated Aug 6, 2024
Reserved Nov 26, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 26, 2014