CVE-2014-9116
mutt - security update
EPSS 9.7%
描述
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
如何修補 CVE-2014-9116
要修補 CVE-2014-9116,請將受影響套件升級到下列已修補版本。
- Debian/mutt—升級至 1.5.23-2 或更新版本
- Debian/mutt—升級至 1.5.20-9+squeeze4 或更新版本
- Debian/mutt—升級至 1.5.21-6.2+deb7u3 或更新版本
CVE-2014-9116 正在被利用嗎?
中等 — EPSS 為 9.7%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.5.23-2
- from 0, < 1.5.20-9+squeeze4
- from 0, < 1.5.21-6.2+deb7u3