An issue was discovered in NeoMutt before 2018-07-16. nntpaddgroup in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
[ { "signature_type": "Function", "deprecated": false, "source": "https://github.com/neomutt/neomutt/commit/6296f7153f0c9d5e5cd3aaf08f9731e56621bdd3", "signature_version": "v1", "target": { "function": "nntp_add_group", "file": "newsrc.c" }, "digest": { "function_hash": "283958313977304392292584054310221264195", "length": 778.0 }, "id": "CVE-2018-14360-26223d8a" }, { "signature_type": "Line", "deprecated": false, "source": "https://github.com/neomutt/neomutt/commit/6296f7153f0c9d5e5cd3aaf08f9731e56621bdd3", "signature_version": "v1", "target": { "file": "newsrc.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "22949362849866079561205632169481397401", "318694296227284192333243648009636989556", "109414897482760330427672215726692697836", "167368589199021586350713300471872194147", "71442541280865976347982071696056747685", "229216589120131795090129208054550453971", "314948816827267199175688180871484737403", "14063714620715534051493051745113361363", "72287658420810810239531489329603176569" ] }, "id": "CVE-2018-14360-f0bb3a7e" } ]