Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 13.10 USN-2147-1 Critical: Mutt Denial of Service Threat

Ubuntu Large Esm H500
The mutt mail client could be made to crash or run programs as yourlogin if it opened a specially crafted email.
=========================================================================Ubuntu Security Notice USN-2147-1
March 13, 2014

mutt vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

The mutt mail client could be made to crash or run programs as your
login if it opened a specially crafted email.

Software Description:
- mutt: text-based mailreader supporting MIME, GPG, PGP and threading

Details:

Beatrice Torracca and Evgeni Golov discovered a buffer overflow
in mutt while expanding addresses when parsing email headers. An
attacker could specially craft an email to cause mutt to crash,
resulting in a denial of service, or possibly execute arbitrary code
with the privileges of the user invoking mutt.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  mutt                            1.5.21-6.4ubuntu1.1
  mutt-patched                    1.5.21-6.4ubuntu1.1

Ubuntu 12.10:
  mutt                            1.5.21-6ubuntu0.1
  mutt-patched                    1.5.21-6ubuntu0.1

Ubuntu 12.04 LTS:
  mutt                            1.5.21-5ubuntu2.1
  mutt-patched                    1.5.21-5ubuntu2.1

Ubuntu 10.04 LTS:
  mutt                            1.5.20-7ubuntu1.2
  mutt-patched                    1.5.20-7ubuntu1.2

After a standard system update you need to restart mutt to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2147-1
  CVE-2014-0467

Package Information:
  https://launchpad.net/ubuntu/+source/mutt/1.5.21-6.4ubuntu1.1
  https://launchpad.net/ubuntu/+source/mutt/1.5.21-6ubuntu0.1
  https://launchpad.net/ubuntu/+source/mutt/1.5.21-5ubuntu2.1
  https://launchpad.net/ubuntu/+source/mutt/1.5.20-7ubuntu1.2

Ubuntu 13.10 USN-2147-1 Critical: Mutt Denial of Service Threat

ubuntu
Calendar Grey March 13, 2014
Dist Ubuntu Esm H88
A flaw in Mutt on Ubuntu risks crashing or executing harmful code through specially designed emails. Guidance for updates provided.
The mutt mail client could be made to crash or run programs as yourlogin if it opened a specially crafted email.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: mutt 1.5.21-6.4ubuntu1.1 mutt-patched 1.5.21-6.4ubuntu1.1 Ubuntu 12.10: mutt 1.5.21-6ubuntu0.1 mutt-patched 1.5.21-6ubuntu0.1 Ubuntu 12.04 LTS: mutt 1.5.21-5ubuntu2.1 mutt-patched 1.5.21-5ubuntu2.1 Ubuntu 10.04 LTS: mutt 1.5.20-7ubuntu1.2 mutt-patched 1.5.20-7ubuntu1.2 After a standard system update you need to restart mutt to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2147-1

CVE-2014-0467

Severity
critical
Lowest
Low
Medium
High
Critical

March 13, 2014

Package Information

https://launchpad.net/ubuntu/+source/mutt/1.5.21-6.4ubuntu1.1 https://launchpad.net/ubuntu/+source/mutt/1.5.21-6ubuntu0.1 https://launchpad.net/ubuntu/+source/mutt/1.5.21-5ubuntu2.1 https://launchpad.net/ubuntu/+source/mutt/1.5.20-7ubuntu1.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here