Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2018:2085-1 Important: Buffer Overflow and Exec Issues

suse
Calendar Grey July 27, 2018
Scroller Suse
SUSE Security Announcement addresses 20 vulnerabilities in mutt, highlighting critical patches and enhancements. Discover further details in this notice.
An update that solves 16 vulnerabilities and has one errata is now available

Summary

This update for mutt fixes the following issues: Security issues fixed: - bsc#1101428: Mutt 1.10.1 security release update. - CVE-2018-14351: Fix imap/command.c that mishandles long IMAP status mailbox literal count size (bsc#1101583). - CVE-2018-14353: Fix imap_quote_string in imap/util.c that has an integer underflow (bsc#1101581). - CVE-2018-14362: Fix pop.c that does not forbid characters that may have unsafe interaction with message-cache pathnames (bsc#1101567). - CVE-2018-14354: Fix arbitrary command execution from remote IMAP servers via backquote characters (bsc#1101578). - CVE-2018-14352: Fix imap_quote_string in imap/util.c that does not leave room for quote characters (bsc#1101582). - CVE-2018-14356: Fix pop.c that mishandles a zero-length UID (bsc#1101576).

References

#1094717 #1101428 #1101566 #1101567 #1101568

#1101569 #1101570 #1101571 #1101573 #1101576

#1101577 #1101578 #1101581 #1101582 #1101583

#1101588 #1101589

Cross- CVE-2014-9116 CVE-2018-14349 CVE-2018-14350

CVE-2018-14351 CVE-2018-14352 CVE-2018-14353

CVE-2018-14354 CVE-2018-14355 CVE-2018-14356

CVE-2018-14357 CVE-2018-14358 CVE-2018-14359

CVE-2018-14360 CVE-2018-14361 CVE-2018-14362

CVE-2018-14363

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2014-9116.html

https://www.suse.com/security/cve/CVE-2018-14349.html

https://www.suse.com/security/cve/CVE-2018-14350.html

https://www.suse.com/security/cve/CVE-2018-14351.html

https://www.suse.com/security/cve/CVE-2018-14352.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2085-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.