PT-2018-3182 · Neomutt+4 · Neomutt+4

CVE-2018-14363

·

Published

2018-07-16

·

Updated

2025-01-15

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions NeoMutt versions prior to 2018-07-16
Description An issue exists due to the improper restriction of '/' characters in the newsrc.c component, potentially leading to unsafe interactions with cache pathnames. This could allow a remote attacker to impact the integrity of protected information.
Recommendations For versions prior to 2018-07-16, update to a version released after 2018-07-16 to resolve the issue. As a temporary workaround, consider restricting access to the newsrc.c component to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2247
ALT-PU-2018-2274
BDU:2019-04313
CVE-2018-14363
DLA-1455-1
DSA-4277-1
MGASA-2018-0447
OPENSUSE-SU-2018_2212-1
OPENSUSE-SU-2019_0052-1
OPENSUSE-SU-2024:11069-1
OPENSUSE-SU-2024:11079-1
SUSE-SU-2018:2084-1
SUSE-SU-2018:2085-1
SUSE-SU-2019:1196-1
USN-7204-1

Affected Products

Alt Linux
Linuxmint
Neomutt
Suse
Ubuntu