An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
[
{
"id": "CVE-2018-14363-5032a5cc",
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Line",
"target": {
"file": "newsrc.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"166461457871203343767825428571992619843",
"332801287067323168050430816170670082991",
"271786472213938683788850057094204643412",
"119372439653162492663372824806615850337"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2018-14363-7c96e5e9",
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"target": {
"file": "newsrc.c",
"function": "nntp_hcache_namer"
},
"deprecated": false,
"digest": {
"length": 137.0,
"function_hash": "267537665779261270121660410598778019730"
},
"signature_version": "v1"
},
{
"id": "CVE-2018-14363-7ee6e997",
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Line",
"target": {
"file": "pop.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"282507869725829356368754754288309731924",
"180075208061962054958382423698787589478",
"325390537779811331403578311429992453917",
"40849553194821509632949074050468769859",
"139842194387533044031811617629497364218",
"155050040835949172408810526580165649552",
"136377786910619544328349675424106556833",
"151860417053105295748988167916222166622",
"244086138280538416743903398152755732605",
"332873696842681422891121565529699034939",
"236007473157134103291937908027325601442",
"216939413199658701745639496112987145005",
"324706117862882001673612538146887821301",
"57129907368067683541711472898614270563",
"213551591269061358836562623901559679350",
"152837113381736160920589610252144188990",
"141585947957200433890708682389411167554",
"5340409753338793195453880600907208224",
"241370935965336750474995126612698116846",
"51823177502555382073407727853414073788",
"82051695059155998028808786658533210318",
"122795335888784005275271044672923481284",
"222778029668092806927494490481893861537",
"224596775040337544067511760021919277960",
"221925278420521875570561763670544009873",
"310573466833311325665692755462274655651",
"35115817430826594319918924333839638986"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2018-14363-8f9282b8",
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"target": {
"file": "pop.c",
"function": "pop_sync_mailbox"
},
"deprecated": false,
"digest": {
"length": 1605.0,
"function_hash": "221900545852017990172313032652197004192"
},
"signature_version": "v1"
},
{
"id": "CVE-2018-14363-dc6726c2",
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"target": {
"file": "pop.c",
"function": "pop_fetch_headers"
},
"deprecated": false,
"digest": {
"length": 3017.0,
"function_hash": "317257631665400846064623998635648083237"
},
"signature_version": "v1"
},
{
"id": "CVE-2018-14363-e1053d8a",
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"target": {
"file": "pop.c",
"function": "msg_cache_check"
},
"deprecated": false,
"digest": {
"length": 502.0,
"function_hash": "126506414352260493509523767341186245450"
},
"signature_version": "v1"
},
{
"id": "CVE-2018-14363-ee32bb20",
"source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e",
"signature_type": "Function",
"target": {
"file": "pop.c",
"function": "pop_fetch_message"
},
"deprecated": false,
"digest": {
"length": 2597.0,
"function_hash": "221749324668458347741321909465042818204"
},
"signature_version": "v1"
}
]