CVE-2014-9116
02.12.2014, 16:59
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mutt | mutt | 1.5.23 |
| debian | debian_linux | 7.0 |
| mageia | mageia | 4.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References