MEDIUM
mutt: buffer overflow in uudecoder function
Published Apr 14, 2022
6.5
MEDIUMCVSS 3.1
EPSS 1.71%
Description
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
Affected products
-
- Version >=0.94.13, <2.2.3StatusaffectedConstraints-
- Version
Configuration 2
- 9.0
Configuration 3
- 36
No data.
Red Hat Enterprise Linux 8
mutt-5:2.0.7-2.el8
Fixed · RHSA-2022:7640
Red Hat Enterprise Linux 9
mutt-5:2.2.6-1.el9
Fixed · RHSA-2022:8219
Red Hat Enterprise Linux 6
mutt
Out of support scope
Red Hat Enterprise Linux 7
mutt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | mutt-5:2.0.7-2.el8 | Fixed | RHSA-2022:7640 |
| Red Hat Enterprise Linux 9 | mutt-5:2.2.6-1.el9 | Fixed | RHSA-2022:8219 |
| Red Hat Enterprise Linux 6 | mutt | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | mutt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2022-1328 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2076058 Issue Tracking
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1328.json Third Party Advisory
- https://gitlab.com/muttmua/mutt/-/commit/e5ed080c00e59701ca62ef9b2a6d2612ebf765a5 PatchThird Party Advisory
- https://gitlab.com/muttmua/mutt/-/issues/404 ExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1328
- https://www.cve.org/CVERecord?id=CVE-2022-1328
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1328 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2076058 | Issue Tracking | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1328.json | Third Party Advisory | |
| https://gitlab.com/muttmua/mutt/-/commit/e5ed080c00e59701ca62ef9b2a6d2612ebf765a5 | PatchThird Party Advisory | |
| https://gitlab.com/muttmua/mutt/-/issues/404 | ExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1328 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-1328 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 14, 2022
Updated Aug 3, 2024
Reserved Apr 12, 2022
Link CVE-2022-1328
CISA Vulnrichment
Updated n/a