An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
[ { "signature_type": "Line", "id": "CVE-2018-14363-5032a5cc", "source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e", "signature_version": "v1", "target": { "file": "newsrc.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "166461457871203343767825428571992619843", "332801287067323168050430816170670082991", "271786472213938683788850057094204643412", "119372439653162492663372824806615850337" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2018-14363-7c96e5e9", "source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e", "signature_version": "v1", "target": { "function": "nntp_hcache_namer", "file": "newsrc.c" }, "digest": { "function_hash": "267537665779261270121660410598778019730", "length": 137.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2018-14363-7ee6e997", "source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e", "signature_version": "v1", "target": { "file": "pop.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "282507869725829356368754754288309731924", "180075208061962054958382423698787589478", "325390537779811331403578311429992453917", "40849553194821509632949074050468769859", "139842194387533044031811617629497364218", "155050040835949172408810526580165649552", "136377786910619544328349675424106556833", "151860417053105295748988167916222166622", "244086138280538416743903398152755732605", "332873696842681422891121565529699034939", "236007473157134103291937908027325601442", "216939413199658701745639496112987145005", "324706117862882001673612538146887821301", "57129907368067683541711472898614270563", "213551591269061358836562623901559679350", "152837113381736160920589610252144188990", "141585947957200433890708682389411167554", "5340409753338793195453880600907208224", "241370935965336750474995126612698116846", "51823177502555382073407727853414073788", "82051695059155998028808786658533210318", "122795335888784005275271044672923481284", "222778029668092806927494490481893861537", "224596775040337544067511760021919277960", "221925278420521875570561763670544009873", "310573466833311325665692755462274655651", "35115817430826594319918924333839638986" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2018-14363-8f9282b8", "source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e", "signature_version": "v1", "target": { "function": "pop_sync_mailbox", "file": "pop.c" }, "digest": { "function_hash": "221900545852017990172313032652197004192", "length": 1605.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2018-14363-dc6726c2", "source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e", "signature_version": "v1", "target": { "function": "pop_fetch_headers", "file": "pop.c" }, "digest": { "function_hash": "317257631665400846064623998635648083237", "length": 3017.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2018-14363-e1053d8a", "source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e", "signature_version": "v1", "target": { "function": "msg_cache_check", "file": "pop.c" }, "digest": { "function_hash": "126506414352260493509523767341186245450", "length": 502.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2018-14363-ee32bb20", "source": "https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e", "signature_version": "v1", "target": { "function": "pop_fetch_message", "file": "pop.c" }, "digest": { "function_hash": "221749324668458347741321909465042818204", "length": 2597.0 }, "deprecated": false } ]