Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-0140

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2003-0140
Last Modified 10 Sep 2008 03:18:02
Published 24 Mar 2003 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2003-0140

Summary

Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.

Vulnerable Systems

Application

  • Mutt 1.3.12

  • Mutt 1.3.16

  • Mutt 1.3.17

  • Mutt 1.3.22

  • Mutt 1.3.24

  • Mutt 1.3.25

  • Mutt 1.3.27

  • Mutt 1.4.0

  • Mutt 1.5.3


References

BID - 7120

BUGTRAQ - 20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent

XF - mutt-folder-name-bo(11583)

BUGTRAQ - 20030319 mutt-1.4.1 fixes a buffer overflow.

REDHAT - RHSA-2003:109

SUSE - SuSE-SA:2003:020

DEBIAN - DSA-268

MANDRAKE - MDKSA-2003:041

GENTOO - GLSA-200303-19

MISC - http://www.coresecurity.com/common/showdoc.php?idx=310&idxseccion=10

BUGTRAQ - 20030430 GLSA: balsa (200304-10)

BUGTRAQ - 20030322 GLSA: mutt (200303-19)

BUGTRAQ - 20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)

CONECTIVA - CLA-2003:630

CONECTIVA - CLA-2003:626


Last Updated: 27 May 2016 10:37:48