SUSE-SU-2019:1196-1 -- SLES muttID: oval:org.secpod.oval:def:89003455 | Date: (C)2021-02-27 (M)2022-10-10 |
Class: PATCH | Family: unix |
This update for mutt fixes the following issues: Security issues fixed: - bsc#1101428: Mutt 1.10.1 security release update. - CVE-2018-14351: Fix imap/command.c that mishandles long IMAP status mailbox literal count size . - CVE-2018-14353: Fix imap_quote_string in imap/util.c that has an integer underflow . - CVE-2018-14362: Fix pop.c that does not forbid characters that may have unsafe interaction with message-cache pathnames . - CVE-2018-14354: Fix arbitrary command execution from remote IMAP servers via backquote characters . - CVE-2018-14352: Fix imap_quote_string in imap/util.c that does not leave room for quote characters . - CVE-2018-14356: Fix pop.c that mishandles a zero-length UID . - CVE-2018-14355: Fix imap/util.c that mishandles quot;..quot; directory traversal in a mailbox name . - CVE-2018-14349: Fix imap/command.c that mishandles a NO response without a message . - CVE-2018-14350: Fix imap/message.c that has a stack-based buffer overflow for a FETCH response with along INTERNALDATE field . - CVE-2018-14363: Fix newsrc.c that does not properlyrestrict "/" characters that may have unsafe interaction with cache pathnames . - CVE-2018-14359: Fix buffer overflow via base64 data . - CVE-2018-14358: Fix imap/message.c that has a stack-based buffer overflow for a FETCH response with along RFC822.SIZE field . - CVE-2018-14360: Fix nntp_add_group in newsrc.c that has a stack-based buffer overflow because of incorrect sscanf usage . - CVE-2018-14357: Fix that remote IMAP servers are allowed to execute arbitrary commands via backquote characters . - CVE-2018-14361: Fix that nntp.c proceeds even if memory allocation fails for messages data . Bug fixes: - mutt reports as neomutt and incorrect version - No sidebar available in mutt 1.6.1 from Tumbleweed snapshot 20160517 - mutt-1.6.1 unusable when built with --enable-sidebar - mutt displaying times in Zulu time - mutt unconditionally segfaults when displaying a message
Platform: |
SUSE Linux Enterprise Server 12 SP3 |