CVE-2014-9116
mutt - security update
EPSS 3.5%
Description
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
How to fix CVE-2014-9116
To remediate CVE-2014-9116, upgrade the affected package to a fixed version below.
- Debian/mutt—upgrade to 1.5.23-2 or later
- Debian/mutt—upgrade to 1.5.20-9+squeeze4 or later
- Debian/mutt—upgrade to 1.5.21-6.2+deb7u3 or later
Is CVE-2014-9116 being exploited?
Low — EPSS is 3.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.5.23-2
- from 0, < 1.5.20-9+squeeze4
- from 0, < 1.5.21-6.2+deb7u3