USN-7204-1

Source
https://ubuntu.com/security/notices/USN-7204-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7204-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7204-1
Related
Published
2025-01-15T16:07:30.088124Z
Modified
2025-01-15T16:07:30.088124Z
Summary
neomutt vulnerabilities
Details

Jeriko One discovered that NeoMutt incorrectly handled certain IMAP and POP3 responses. An attacker could possibly use this issue to cause NeoMutt to crash, resulting in a denial of service, or the execution of arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-14349, CVE-2018-14350, CVE-2018-14351, CVE-2018-14352, CVE-2018-14353, CVE-2018-14354, CVE-2018-14355, CVE-2018-14356, CVE-2018-14357, CVE-2018-14358, CVE-2018-14359, CVE-2018-14362)

Jeriko One discovered that NeoMutt incorrectly handled certain NNTP-related operations. An attacker could possibly use this issue to cause NeoMutt to crash, resulting in denial of service, or the execution of arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-14360, CVE-2018-14361, CVE-2018-14363)

It was discovered that NeoMutt incorrectly processed additional data when communicating with mail servers. An attacker could possibly use this issue to access senstive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14954, CVE-2020-28896)

It was discovered that Neomutt incorrectly handled the IMAP QRSync setting. An attacker could possibly use this issue to cause NeoMutt to crash, resulting in denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-32055)

Tavis Ormandy discovered that NeoMutt incorrectly parsed uuencoded text past the length of the string. An attacker could possibly use this issue to enable the execution of arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-1328)

It was discovered that NeoMutt did not properly encrypt email headers. An attacker could possibly use this issue to receive emails that were not intended for them and access sensitive information. This vulnerability was only fixed in Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-49393, CVE-2024-49394)

References

Affected packages

Ubuntu:Pro:18.04:LTS / neomutt

Package

Name
neomutt
Purl
pkg:deb/ubuntu/neomutt@20171215+dfsg.1-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20171215+dfsg.1-1ubuntu0.1~esm1

Affected versions

Other

20171027-1
20171027-2

20171027+dfsg.*

20171027+dfsg.1-1
20171027+dfsg.1-2
20171027+dfsg.1-4

20171208+dfsg.*

20171208+dfsg.1-1
20171208+dfsg.1-2

20171215+dfsg.*

20171215+dfsg.1-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "20171215+dfsg.1-1ubuntu0.1~esm1",
            "binary_name": "neomutt"
        },
        {
            "binary_version": "20171215+dfsg.1-1ubuntu0.1~esm1",
            "binary_name": "neomutt-dbgsym"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / neomutt

Package

Name
neomutt
Purl
pkg:deb/ubuntu/neomutt@20191207+dfsg.1-1.1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20191207+dfsg.1-1.1ubuntu0.1~esm1

Affected versions

20180716+dfsg.*

20180716+dfsg.1-1.2

20191111+dfsg.*

20191111+dfsg.1-1

20191207+dfsg.*

20191207+dfsg.1-1.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "20191207+dfsg.1-1.1ubuntu0.1~esm1",
            "binary_name": "neomutt"
        },
        {
            "binary_version": "20191207+dfsg.1-1.1ubuntu0.1~esm1",
            "binary_name": "neomutt-dbgsym"
        }
    ]
}

Ubuntu:Pro:22.04:LTS / neomutt

Package

Name
neomutt
Purl
pkg:deb/ubuntu/neomutt@20211029+dfsg1-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20211029+dfsg1-1ubuntu0.1~esm1

Affected versions

20201127+dfsg.*

20201127+dfsg.1-1.2

Other

20211029+dfsg1-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "20211029+dfsg1-1ubuntu0.1~esm1",
            "binary_name": "neomutt"
        },
        {
            "binary_version": "20211029+dfsg1-1ubuntu0.1~esm1",
            "binary_name": "neomutt-dbgsym"
        }
    ]
}

Ubuntu:Pro:24.04:LTS / neomutt

Package

Name
neomutt
Purl
pkg:deb/ubuntu/neomutt@20231103+dfsg1-1ubuntu0.1~esm1?arch=source&distro=esm-apps/noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20231103+dfsg1-1ubuntu0.1~esm1

Affected versions

20220429+dfsg1-4.*

20220429+dfsg1-4.1

Other

20231103+dfsg1-1
20231103+dfsg1-1build2
20231103+dfsg1-1build3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "20231103+dfsg1-1ubuntu0.1~esm1",
            "binary_name": "neomutt"
        },
        {
            "binary_version": "20231103+dfsg1-1ubuntu0.1~esm1",
            "binary_name": "neomutt-dbgsym"
        }
    ]
}