9.8
CVSSv3

CVE-2018-14357

Published: 17/07/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Mutt prior to 1.10.1 and NeoMutt prior to 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mutt mutt

neomutt neomutt

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

debian debian linux 8.0

debian debian linux 9.0

redhat enterprise linux desktop 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server 6.0

redhat enterprise linux server 7.0

redhat enterprise linux server aus 7.6

redhat enterprise linux server aus 7.7

redhat enterprise linux server eus 7.5

redhat enterprise linux server eus 7.6

redhat enterprise linux server eus 7.7

redhat enterprise linux server tus 7.6

redhat enterprise linux server tus 7.7

redhat enterprise linux workstation 6.0

redhat enterprise linux workstation 7.0

Vendor Advisories

Synopsis Important: mutt security update Type/Severity Security Advisory: Important Topic An update for mutt is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Debian Bug report logs - #904021 neomutt: CVE-2018-14349 CVE-2018-14350 CVE-2018-14351 CVE-2018-14352 CVE-2018-14353 CVE-2018-14354 CVE-2018-14355 CVE-2018-14356 CVE-2018-14357 CVE-2018-14358 CVE-2018-14359 CVE-2018-14360 CVE-2018-14361 CVE-2018-14362 CVE-2018-14363 Package: src:neomutt; Maintainer for src:neomutt is Mutt maintainers < ...
Several vulnerabilities were discovered in Mutt, a text-based mailreader supporting MIME, GPG, PGP and threading, potentially leading to code execution, denial of service or information disclosure when connecting to a malicious mail/NNTP server For the stable distribution (stretch), these problems have been fixed in version 172-1+deb9u1 We reco ...
Several security issues were fixed in Mutt ...
Several security issues were fixed in Mutt ...
Several security issues were fixed in Mutt ...
An issue was discovered in Mutt before 1101 and NeoMutt before 2018-07-16 popc does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character(CVE-2018-14362) An issue was discovered in Mutt before 1101 and NeoMutt before 2018-07-16 They allow remote IMAP servers to execute arbitr ...
An issue was discovered in Mutt before 1101 and NeoMutt before 2018-07-16 They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription ...
An issue was discovered in Mutt before 1101 and NeoMutt before 2018-07-16 They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription ...