CVE-2014-9116
Publication date 2 December 2014
Last updated 24 July 2024
Ubuntu priority
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
Status
Package | Ubuntu Release | Status |
---|---|---|
mutt | ||
14.04 LTS trusty |
Fixed 1.5.21-6.4ubuntu2.1
|
|
Notes
Patch details
Package | Patch details |
---|---|
mutt |
References
Related Ubuntu Security Notices (USN)
- USN-2440-1
- Mutt vulnerability
- 11 December 2014