CVE-2018-14354

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-14354
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14354.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-14354
Related
Published
2018-07-17T17:29:00Z
Modified
2024-10-12T03:12:55.427942Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.

References

Affected packages

Alpine:v3.5 / mutt

Package

Name
mutt
Purl
pkg:apk/alpine/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-r0

Affected versions

1.*

1.4.2.3-r0
1.4.2.3-r1
1.4.2.3-r2
1.4.2.3-r3
1.4.2.3-r4
1.4.2.3-r5
1.5.21-r0
1.5.21-r1
1.5.21-r2
1.5.22-r0
1.5.23-r0
1.5.23-r1
1.5.24-r1
1.5.24-r2
1.5.24-r3
1.6.0-r0
1.6.1-r0
1.6.2-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.1-r1
1.7.2-r0

Alpine:v3.6 / mutt

Package

Name
mutt
Purl
pkg:apk/alpine/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-r0

Affected versions

1.*

1.4.2.3-r0
1.4.2.3-r1
1.4.2.3-r2
1.4.2.3-r3
1.4.2.3-r4
1.4.2.3-r5
1.5.21-r0
1.5.21-r1
1.5.21-r2
1.5.22-r0
1.5.23-r0
1.5.23-r1
1.5.24-r1
1.5.24-r2
1.5.24-r3
1.6.0-r0
1.6.1-r0
1.6.2-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.1-r1
1.7.2-r0
1.7.2-r1
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.2-r0
1.8.3-r0

Alpine:v3.7 / mutt

Package

Name
mutt
Purl
pkg:apk/alpine/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-r0

Affected versions

1.*

1.4.2.3-r0
1.4.2.3-r1
1.4.2.3-r2
1.4.2.3-r3
1.4.2.3-r4
1.4.2.3-r5
1.5.21-r0
1.5.21-r1
1.5.21-r2
1.5.22-r0
1.5.23-r0
1.5.23-r1
1.5.24-r1
1.5.24-r2
1.5.24-r3
1.6.0-r0
1.6.1-r0
1.6.2-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.1-r1
1.7.2-r0
1.7.2-r1
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.2-r0
1.8.3-r0
1.9.0-r0
1.9.1-r0
1.9.1-r1

Alpine:v3.8 / mutt

Package

Name
mutt
Purl
pkg:apk/alpine/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-r0

Affected versions

1.*

1.4.2.3-r0
1.4.2.3-r1
1.4.2.3-r2
1.4.2.3-r3
1.4.2.3-r4
1.4.2.3-r5
1.5.21-r0
1.5.21-r1
1.5.21-r2
1.5.22-r0
1.5.23-r0
1.5.23-r1
1.5.24-r1
1.5.24-r2
1.5.24-r3
1.6.0-r0
1.6.1-r0
1.6.2-r0
1.7.0-r0
1.7.0-r1
1.7.1-r0
1.7.1-r1
1.7.2-r0
1.7.2-r1
1.8.0-r0
1.8.1-r0
1.8.1-r1
1.8.2-r0
1.8.3-r0
1.9.0-r0
1.9.1-r0
1.9.1-r1
1.9.2-r0
1.9.3-r0
1.9.4-r0
1.9.4-r1
1.9.5-r0
1.10.0-r0

Debian:11 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / mutt

Package

Name
mutt
Purl
pkg:deb/debian/mutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20180716+dfsg.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20180716+dfsg.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / neomutt

Package

Name
neomutt
Purl
pkg:deb/debian/neomutt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20180716+dfsg.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/muttmua/mutt

Affected ranges

Type
GIT
Repo
https://github.com/muttmua/mutt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/neomutt/neomutt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://gitlab.com/muttmua/mutt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

mutt-0-92-10i
mutt-0-92-11i
mutt-0-92-9i
mutt-0-93-unstable
mutt-0-94-10i-rel
mutt-0-94-13-rel
mutt-0-94-14-rel
mutt-0-94-15-rel
mutt-0-94-16i-rel
mutt-0-94-17i-rel
mutt-0-94-18-rel
mutt-0-94-5i-rel
mutt-0-94-6i-rel
mutt-0-94-7i-rel
mutt-0-94-8i-rel
mutt-0-94-9i-p1
mutt-0-94-9i-rel
mutt-0-95-rel
mutt-0-96-1-rel
mutt-0-96-2-slightly-post-release
mutt-0-96-3-rel
mutt-0-96-4-rel
mutt-0-96-5-rel
mutt-0-96-6-rel
mutt-0-96-7-rel
mutt-0-96-8-rel
mutt-0-96-rel
mutt-1-1-1-1-rel
mutt-1-1-1-2-rel
mutt-1-1-1-rel
mutt-1-1-10-rel
mutt-1-1-11-rel
mutt-1-1-12-rel
mutt-1-1-13-rel
mutt-1-1-14-rel
mutt-1-1-2-rel
mutt-1-1-3-rel
mutt-1-1-4-rel
mutt-1-1-5-rel
mutt-1-1-6-rel
mutt-1-1-7-rel
mutt-1-1-8-rel
mutt-1-1-9-rel
mutt-1-1-rel
mutt-1-10-rel
mutt-1-3-1-rel
mutt-1-3-10-rel
mutt-1-3-11-rel
mutt-1-3-12-rel
mutt-1-3-13-rel
mutt-1-3-14-rel
mutt-1-3-15-rel
mutt-1-3-16-rel
mutt-1-3-17-rel
mutt-1-3-18-rel
mutt-1-3-19-rel
mutt-1-3-2-rel
mutt-1-3-20-rel
mutt-1-3-21-rel
mutt-1-3-22-1-rel
mutt-1-3-22-rel
mutt-1-3-23-1-rel
mutt-1-3-23-2-rel
mutt-1-3-23-rel
mutt-1-3-24-rel
mutt-1-3-25-rel
mutt-1-3-26-rel
mutt-1-3-27-rel
mutt-1-3-3-rel
mutt-1-3-4-rel
mutt-1-3-5-rel
mutt-1-3-6-rel
mutt-1-3-7-rel
mutt-1-3-8-rel
mutt-1-3-9-rel
mutt-1-3-rel
mutt-1-5-1-rel
mutt-1-5-10-rel
mutt-1-5-11-rel
mutt-1-5-12-rel
mutt-1-5-13-rel
mutt-1-5-14-rel
mutt-1-5-15-rel
mutt-1-5-16-rel
mutt-1-5-17-rel
mutt-1-5-18-rel
mutt-1-5-19-rel
mutt-1-5-2-rel
mutt-1-5-20-rel
mutt-1-5-21-rel
mutt-1-5-22-rel
mutt-1-5-23-rel
mutt-1-5-24-rel
mutt-1-5-3-rel
mutt-1-5-4-rel
mutt-1-5-5-1-rel
mutt-1-5-5-rel
mutt-1-5-6-rel
mutt-1-5-7-rel
mutt-1-5-8-rel
mutt-1-5-9-rel
mutt-1-6-1-rel
mutt-1-6-2-rel
mutt-1-6-rel
mutt-1-7-1-rel
mutt-1-7-2-rel
mutt-1-7-rel
mutt-1-8-1-rel
mutt-1-8-2-rel
mutt-1-8-3-rel
mutt-1-8-rel
mutt-1-9-1-rel
mutt-1-9-2-rel
mutt-1-9-3-rel
mutt-1-9-4-rel
mutt-1-9-5-rel
mutt-1-9-rel
neomutt-20160822
neomutt-20160827
neomutt-20160910
neomutt-20160916
neomutt-20161002
neomutt-20161003
neomutt-20161014
neomutt-20161028
neomutt-20161104
neomutt-20161126
neomutt-20170113
neomutt-20170128
neomutt-20170206
neomutt-20170225
neomutt-20170306
neomutt-20170414
neomutt-20170421
neomutt-20170428
neomutt-20170526
neomutt-20170602
neomutt-20170609
neomutt-20170707
neomutt-20170714
neomutt-20170907
neomutt-20170912
neomutt-20171006
neomutt-20171013
neomutt-20171027
neomutt-20171208
neomutt-20171215
neomutt-20180223
neomutt-20180323
neomutt-20180512
neomutt-20180622
post-type-punning-patch
pre-type-punning-patch