CVE Database
/

CVE-2014-9116

Back to search

CVE-2014-9116

Published: Dec 2, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2015:0012
vendor-advisory
x_refsource_SUSE
1031266
vdb-entry
x_refsource_SECTRACK
MDVSA-2015:078
vendor-advisory
x_refsource_MANDRIVA
GLSA-201701-04
vendor-advisory
x_refsource_GENTOO
71334
vdb-entry
x_refsource_BID
DSA-3083
vendor-advisory
x_refsource_DEBIAN
MDVSA-2014:245
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now