An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
[
{
"target": {
"function": "pop_sync_mailbox",
"file": "pop.c"
},
"id": "CVE-2018-14362-220a3e57",
"deprecated": false,
"digest": {
"length": 1554.0,
"function_hash": "203877282032082513856670457410106984505"
},
"signature_type": "Function",
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_version": "v1"
},
{
"target": {
"function": "msg_cache_check",
"file": "pop.c"
},
"id": "CVE-2018-14362-49a43789",
"deprecated": false,
"digest": {
"length": 508.0,
"function_hash": "325500082941333257680736014199074461078"
},
"signature_type": "Function",
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_version": "v1"
},
{
"target": {
"file": "pop.c"
},
"id": "CVE-2018-14362-6549483d",
"deprecated": false,
"digest": {
"line_hashes": [
"249015905104921783268118379981716813190",
"180075208061962054958382423698787589478",
"325390537779811331403578311429992453917",
"278699521853201390138733764370018106823",
"136146737738893881373200863103551512706",
"37946969253956364904725322594086040643",
"136377786910619544328349675424106556833",
"252327019854101608580927746545791717975",
"311774669800139807448699864180319932977",
"312391031714537274799489084210941021847",
"65533333092715524251554559761039476142",
"319048243970272962809421998665251142787",
"15399704111583966608829171321511557541",
"139248657884988144472504769782390882235",
"100776044121495972102910698871361049635",
"233062047643696112113804803750618361816",
"255431875871928149974607115155767126849",
"141430068407181609594324196064843873604",
"272757196427394987088838092283140012902",
"51823177502555382073407727853414073788",
"82051695059155998028808786658533210318",
"122795335888784005275271044672923481284",
"222778029668092806927494490481893861537",
"178986409078730298952473038896566632911",
"118940702271776095458127372552951708946",
"253565662786306008209989016921826687734",
"67385587830157418889556558718074387589"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_version": "v1"
},
{
"target": {
"function": "pop_fetch_headers",
"file": "pop.c"
},
"id": "CVE-2018-14362-6f134f7b",
"deprecated": false,
"digest": {
"length": 2980.0,
"function_hash": "299808168449394784185784048087150085601"
},
"signature_type": "Function",
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_version": "v1"
},
{
"target": {
"function": "pop_fetch_message",
"file": "pop.c"
},
"id": "CVE-2018-14362-f506d620",
"deprecated": false,
"digest": {
"length": 2632.0,
"function_hash": "227203994769922844282177250937303926350"
},
"signature_type": "Function",
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14362.json"