Описание
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| neomutt | fixed | 20180716+dfsg.1-1 | package | |
| mutt | fixed | 1.9.1-1 | package |
Примечания
https://github.com/neomutt/neomutt/commit/6296f7153f0c9d5e5cd3aaf08f9731e56621bdd3
src:mutt 1.9.1-1 switches to official mutt.org source code without neomutt patchset
previous versions ship a neomutt patchset.
EPSS
Связанные уязвимости
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
Уязвимость функции sscanf в файле newsrc.c почтового клиента NeoMutt, связанная с ошибками при обработке объектов в памяти, позволяющая нарушителю выполнить произвольный код
EPSS