ALAS-2023-1865

Related Vulnerabilities: CVE-2022-1328  

A flaw was found in mutt. When reading unencoded messages, mutt uses the line length from the untrusted input without any validation. This flaw allows an attacker to craft a malicious message, which leads to an out-of-bounds read, causing data leaks that include fragments of other unrelated messages. (CVE-2022-1328)

ALAS-2023-1865


Amazon Linux 1 Security Advisory: ALAS-2023-1865
Advisory Release Date: 2023-10-12 15:48 Pacific
Advisory Updated Date: 2023-10-24 21:37 Pacific
Severity: Medium

Issue Overview:

A flaw was found in mutt. When reading unencoded messages, mutt uses the line length from the untrusted input without any validation. This flaw allows an attacker to craft a malicious message, which leads to an out-of-bounds read, causing data leaks that include fragments of other unrelated messages. (CVE-2022-1328)


Affected Packages:

mutt


Issue Correction:
Run yum update mutt to update your system.

New Packages:
i686:
    mutt-debuginfo-1.5.20-7.20091214hg736b6a.11.amzn1.i686
    mutt-1.5.20-7.20091214hg736b6a.11.amzn1.i686

src:
    mutt-1.5.20-7.20091214hg736b6a.11.amzn1.src

x86_64:
    mutt-debuginfo-1.5.20-7.20091214hg736b6a.11.amzn1.x86_64
    mutt-1.5.20-7.20091214hg736b6a.11.amzn1.x86_64