HIGH
An issue was discovered in NeoMutt before 2018-07-16
Published Jul 17, 2018
7.5
HIGHCVSS 3.1
EPSS 2.18%
Description
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
Affected products
No data.
Configuration 1
OR
- 8.0
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6284 Advisory
- https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://neomutt.org/2018/07/16/release x_refsource_MISCRelease NotesVendor Advisory
- https://www.debian.org/security/2018/dsa-4277 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6284 | Advisory | |
| https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://neomutt.org/2018/07/16/release | x_refsource_MISCRelease NotesVendor Advisory | |
| https://www.debian.org/security/2018/dsa-4277 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 17, 2018
Updated Aug 5, 2024
Reserved Jul 17, 2018
Link CVE-2018-14363
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data