Описание
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
A flaw was found in mutt, an email client. The url_pct_decode function, which is responsible for decoding URL-encoded strings, does not correctly handle null termination characters. This vulnerability could allow a remote attacker, to manipulate how URLs are processed, potentially leading to a limited loss of data integrity.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | mutt | Out of support scope | ||
| Red Hat Enterprise Linux 6 | mutt | Out of support scope | ||
| Red Hat Enterprise Linux 7 | mutt | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mutt | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mutt | Fix deferred |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-170
https://bugzilla.redhat.com/show_bug.cgi?id=2464868mutt: Mutt: URL processing vulnerability due to improper null character handling
EPSS
Процентиль: 6%
0.00162
Низкий
3.7 Low
CVSS3
Связанные уязвимости
CVSS3: 3.7
ubuntu
3 месяца назад
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
CVSS3: 3.7
nvd
3 месяца назад
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
CVSS3: 3.7
debian
3 месяца назад
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
CVSS3: 3.7
github
3 месяца назад
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
EPSS
Процентиль: 6%
0.00162
Низкий
3.7 Low
CVSS3