Search CVE reports
1 – 10 of 22 results
CVE-2024-49395
Medium priorityIn mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
neomutt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
CVE-2024-49394
Medium priorityIn mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
neomutt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
CVE-2024-49393
Medium priorityIn neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise...
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
neomutt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
CVE-2022-1328
Medium prioritySome fixes available 10 of 19
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Fixed | Fixed | Fixed | Fixed | Fixed |
neomutt | Needs evaluation | Needs evaluation | Vulnerable | Vulnerable | Ignored |
CVE-2021-32055
Low prioritySome fixes available 2 of 15
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the...
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Not affected | Not affected | Fixed | Not affected | Fixed |
neomutt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Ignored |
CVE-2020-28896
Medium prioritySome fixes available 4 of 7
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue...
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Not affected | Not affected | Fixed | Fixed | Fixed |
neomutt | Not affected | Not affected | Needs evaluation | Needs evaluation | Not in release |
CVE-2020-14954
Medium prioritySome fixes available 4 of 7
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a...
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Not affected | Not affected | Fixed | Fixed | Fixed |
neomutt | Not affected | Not affected | Needs evaluation | Needs evaluation | Not in release |
CVE-2018-14363
Medium priorityAn issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
1 affected packages
neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2018-14361
Medium priorityAn issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
1 affected packages
neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2018-14360
Medium priorityAn issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
1 affected packages
neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |