DSA-274-1 mutt -- buffer overflow

Related Vulnerabilities: CVE-2003-0167  

Byrial Jensen discovered a couple of off-by-one buffer overflow in the IMAP code of Mutt, a text-oriented mail reader supporting IMAP, MIME, GPG, PGP and threading. This problem could potentially allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder. For the stable distribution (woody) this problem has been fixed in version 1.3.28-2.2. The old stable distribution (potato) is also affected by this problem and an update will follow. For the unstable distribution (sid) this problem has been fixed in version 1.4.0 and above. We recommend that you upgrade your mutt package.

Debian Security Advisory

DSA-274-1 mutt -- buffer overflow

Date Reported:
28 Mar 2003
Affected Packages:
mutt
Vulnerable:
Yes
Security database references:
In the Bugtraq database (at SecurityFocus): BugTraq ID 7229.
In Mitre's CVE dictionary: CVE-2003-0167.
More information:

Byrial Jensen discovered a couple of off-by-one buffer overflow in the IMAP code of Mutt, a text-oriented mail reader supporting IMAP, MIME, GPG, PGP and threading. This problem could potentially allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder.

For the stable distribution (woody) this problem has been fixed in version 1.3.28-2.2.

The old stable distribution (potato) is also affected by this problem and an update will follow.

For the unstable distribution (sid) this problem has been fixed in version 1.4.0 and above.

We recommend that you upgrade your mutt package.

Fixed in:

Debian GNU/Linux 2.2 (potato)

Source:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2.dsc
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2.diff.gz
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_m68k.deb
PowerPC:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_powerpc.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.2.5-5.2_sparc.deb

Debian GNU/Linux 3.0 (woody)

Source:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2.dsc
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2.diff.gz
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_alpha.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_arm.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_i386.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_ia64.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_hppa.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_m68k.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_mips.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_mipsel.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_s390.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/m/mutt/mutt_1.3.28-2.2_sparc.deb
http://security.debian.org/pool/updates/main/m/mutt/mutt-utf8_1.3.28-2.2_sparc.deb

MD5 checksums of the listed files are available in the original advisory.

MD5 checksums of the listed files are available in the revised advisory.