The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mutt | Jul 30, 2024 | Dec 2, 2014 |
| Freebsd | — | Upgrade ja-muttUpgrade zh-muttUpgrade mutt | Dec 10, 2025 | Dec 23, 2014 |
| Gentoo Linux | — | Upgrade mail-client/mutt. | Oct 30, 2017 | Dec 2, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 26, 2014 |
| Suse | — | Upgrade mutt-docUpgrade muttUpgrade mutt-lang | Dec 18, 2015 | Dec 2, 2014 |
| Ubuntu | — | Upgrade muttUpgrade mutt-patched | Nov 8, 2024 | Dec 2, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub