Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv99-5p2c-93vv

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

EPSS

Процентиль: 85%
0.02619
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
около 11 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

redhat
около 11 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

nvd
около 11 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

debian
около 11 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle ...

suse-cvrf
почти 12 лет назад

Security update for mutt

EPSS

Процентиль: 85%
0.02619
Низкий

Дефекты

CWE-119