Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9116

Опубликовано: 26 нояб. 2014
Источник: redhat
CVSS2: 2.6

Описание

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5muttNot affected
Red Hat Enterprise Linux 6muttWill not fix
Red Hat Enterprise Linux 7muttWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119->CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1168463mutt: incorrect use of mutt_substrdup() in write_one_header()

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

nvd
около 11 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

debian
около 11 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle ...

github
больше 3 лет назад

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

suse-cvrf
почти 12 лет назад

Security update for mutt

2.6 Low

CVSS2