An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
[
{
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"166461457871203343767825428571992619843",
"332801287067323168050430816170670082991",
"271786472213938683788850057094204643412",
"119372439653162492663372824806615850337"
]
},
"id": "CVE-2018-14362-5032a5cc",
"signature_version": "v1",
"target": {
"file": "newsrc.c"
},
"deprecated": false
},
{
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"digest": {
"function_hash": "267537665779261270121660410598778019730",
"length": 137.0
},
"id": "CVE-2018-14362-7c96e5e9",
"signature_version": "v1",
"target": {
"function": "nntp_hcache_namer",
"file": "newsrc.c"
},
"deprecated": false
},
{
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"282507869725829356368754754288309731924",
"180075208061962054958382423698787589478",
"325390537779811331403578311429992453917",
"40849553194821509632949074050468769859",
"139842194387533044031811617629497364218",
"155050040835949172408810526580165649552",
"136377786910619544328349675424106556833",
"151860417053105295748988167916222166622",
"244086138280538416743903398152755732605",
"332873696842681422891121565529699034939",
"236007473157134103291937908027325601442",
"216939413199658701745639496112987145005",
"324706117862882001673612538146887821301",
"57129907368067683541711472898614270563",
"213551591269061358836562623901559679350",
"152837113381736160920589610252144188990",
"141585947957200433890708682389411167554",
"5340409753338793195453880600907208224",
"241370935965336750474995126612698116846",
"51823177502555382073407727853414073788",
"82051695059155998028808786658533210318",
"122795335888784005275271044672923481284",
"222778029668092806927494490481893861537",
"224596775040337544067511760021919277960",
"221925278420521875570561763670544009873",
"310573466833311325665692755462274655651",
"35115817430826594319918924333839638986"
]
},
"id": "CVE-2018-14362-7ee6e997",
"signature_version": "v1",
"target": {
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"digest": {
"function_hash": "221900545852017990172313032652197004192",
"length": 1605.0
},
"id": "CVE-2018-14362-8f9282b8",
"signature_version": "v1",
"target": {
"function": "pop_sync_mailbox",
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"digest": {
"function_hash": "317257631665400846064623998635648083237",
"length": 3017.0
},
"id": "CVE-2018-14362-dc6726c2",
"signature_version": "v1",
"target": {
"function": "pop_fetch_headers",
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"digest": {
"function_hash": "126506414352260493509523767341186245450",
"length": 502.0
},
"id": "CVE-2018-14362-e1053d8a",
"signature_version": "v1",
"target": {
"function": "msg_cache_check",
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"digest": {
"function_hash": "221749324668458347741321909465042818204",
"length": 2597.0
},
"id": "CVE-2018-14362-ee32bb20",
"signature_version": "v1",
"target": {
"function": "pop_fetch_message",
"file": "pop.c"
},
"deprecated": false
}
]
[
{
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_type": "Function",
"digest": {
"function_hash": "203877282032082513856670457410106984505",
"length": 1554.0
},
"id": "CVE-2018-14362-220a3e57",
"signature_version": "v1",
"target": {
"function": "pop_sync_mailbox",
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_type": "Function",
"digest": {
"function_hash": "325500082941333257680736014199074461078",
"length": 508.0
},
"id": "CVE-2018-14362-49a43789",
"signature_version": "v1",
"target": {
"function": "msg_cache_check",
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"249015905104921783268118379981716813190",
"180075208061962054958382423698787589478",
"325390537779811331403578311429992453917",
"278699521853201390138733764370018106823",
"136146737738893881373200863103551512706",
"37946969253956364904725322594086040643",
"136377786910619544328349675424106556833",
"252327019854101608580927746545791717975",
"311774669800139807448699864180319932977",
"312391031714537274799489084210941021847",
"65533333092715524251554559761039476142",
"319048243970272962809421998665251142787",
"15399704111583966608829171321511557541",
"139248657884988144472504769782390882235",
"100776044121495972102910698871361049635",
"233062047643696112113804803750618361816",
"255431875871928149974607115155767126849",
"141430068407181609594324196064843873604",
"272757196427394987088838092283140012902",
"51823177502555382073407727853414073788",
"82051695059155998028808786658533210318",
"122795335888784005275271044672923481284",
"222778029668092806927494490481893861537",
"178986409078730298952473038896566632911",
"118940702271776095458127372552951708946",
"253565662786306008209989016921826687734",
"67385587830157418889556558718074387589"
]
},
"id": "CVE-2018-14362-6549483d",
"signature_version": "v1",
"target": {
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_type": "Function",
"digest": {
"function_hash": "299808168449394784185784048087150085601",
"length": 2980.0
},
"id": "CVE-2018-14362-6f134f7b",
"signature_version": "v1",
"target": {
"function": "pop_fetch_headers",
"file": "pop.c"
},
"deprecated": false
},
{
"source": "https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576",
"signature_type": "Function",
"digest": {
"function_hash": "227203994769922844282177250937303926350",
"length": 2632.0
},
"id": "CVE-2018-14362-f506d620",
"signature_version": "v1",
"target": {
"function": "pop_fetch_message",
"file": "pop.c"
},
"deprecated": false
}
]