Mutt 'mutt _ substrdup () 'Function Heap Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
Mutt <1.5.23
Description:
Bugtraq id: 71334
CVE (CAN) ID: CVE-2014-9116
Mutt is a Mail reader that supports IMAP, MIME, GPG, and PGP.
The mutt_substrdup () function of versions earlier than Mutt 1.5.23 does not perform correct boundary checks. a heap buffer overflow vulnerability exists in implementation. Remote attackers can exploit this vulnerability to execute arbitrary code in the context of the affected system.
<* Source: Jakub Wilk
*>
Suggestion:
Vendor patch:
Mutt
----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.mutt.org/
Refer:
Http://seclists.org/oss-sec/2014/q4/831
Http://seclists.org/oss-sec/2014/q4/835
This article permanently updates the link address: