Directory Traversal Vulnerability in Mutt and NeoMutt Email Clients
CVE-2018-14355

5.3MEDIUM

Key Information:

Vendor

Debian

Vendor
CVE Published:
17 July 2018

What is CVE-2018-14355?

A directory traversal vulnerability exists in Mutt and NeoMutt email clients that can potentially allow an attacker to manipulate mailbox names using '..' sequences in paths. This flaw can lead to unauthorized access to sensitive information within a user's mailbox. Users are advised to update their email clients to secure versions to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.