Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14362

Опубликовано: 16 июл. 2018
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5muttNot affected
Red Hat Enterprise Linux 8muttNot affected
Red Hat Enterprise Linux 6muttFixedRHSA-2018:252620.08.2018
Red Hat Enterprise Linux 7muttFixedRHSA-2018:252620.08.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1602079mutt: POP body caching path traversal vulnerability

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.

CVSS3: 9.8
nvd
больше 7 лет назад

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.

CVSS3: 9.8
debian
больше 7 лет назад

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018- ...

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость в коде «pop.c» почтовых клиентов Mutt и NeoMutt, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

6.5 Medium

CVSS3