PT-2018-3182 · Neomutt+4 · Neomutt+4
CVE-2018-14363
·
Publicado
2018-07-16
·
Atualizado
2025-01-15
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
NeoMutt versions prior to 2018-07-16
Description
An issue exists due to the improper restriction of '/' characters in the newsrc.c component, potentially leading to unsafe interactions with cache pathnames. This could allow a remote attacker to impact the integrity of protected information.
Recommendations
For versions prior to 2018-07-16, update to a version released after 2018-07-16 to resolve the issue. As a temporary workaround, consider restricting access to the newsrc.c component to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linuxmint
Neomutt
Suse
Ubuntu