Bug 1101428 - VUL-0: mutt,neomutt: code injection and a couple path traversal vulnerabilities
VUL-0: mutt,neomutt: code injection and a couple path traversal vulnerabilities
Status: RESOLVED MOVED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: unspecified
Assigned To: Dr. Werner Fink
Security Team bot
https://smash.suse.de/issue/210754/
:
Depends on: CVE-2018-14363 CVE-2018-14362 CVE-2018-14361 CVE-2018-14360 CVE-2018-14359 CVE-2018-14358 CVE-2018-14357 CVE-2018-14356 CVE-2018-14355 CVE-2018-14354 CVE-2018-14353 CVE-2018-14352 CVE-2018-14351 CVE-2018-14350 CVE-2018-14349
Blocks:
  Show dependency treegraph
 
Reported: 2018-07-17 09:15 UTC by Karol Babioch
Modified: 2019-05-09 10:09 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
1.10.1.diff (36.48 KB, patch)
2018-07-17 09:18 UTC, Karol Babioch
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-07-17 09:15:19 UTC
The NEWS file [1] does not mention any specifics, only this text:

Mutt 1.10.1 was released on July 16, 2018. This is an important bug-fix release, fixing a code injection and a couple path traversal vulnerabilities.

[1]: http://www.mutt.org/news.html
Comment 1 Karol Babioch 2018-07-17 09:18:32 UTC
Created attachment 777122 [details]
1.10.1.diff
Comment 2 Dr. Werner Fink 2018-07-17 09:29:14 UTC
I'm pretty sure that NeoMutt due similar code base has the same problems as well ... adding David to carbon copy list

Beside this: the change in gpg.rc from contrib is not automatically back portable to the users ~/.gpg.rc !
Comment 3 Dr. Werner Fink 2018-07-17 09:30:08 UTC
(In reply to Dr. Werner Fink from comment #2)
> I'm pretty sure that NeoMutt due similar code base has the same problems as
> well ... adding David to carbon copy list

Repeat this part for David as well
Comment 4 David Sterba 2018-07-17 10:42:38 UTC
Thanks. The fix from mutt is present in neomutt, the fixed package is on the way to factory, referencing this bug.
Comment 5 Swamp Workflow Management 2018-07-17 11:50:05 UTC
This is an autogenerated message for OBS integration:
This bug (1101428) was mentioned in
https://build.opensuse.org/request/show/623357 Factory / neomutt
https://build.opensuse.org/request/show/623363 Factory / mutt
Comment 6 Karol Babioch 2018-07-18 07:45:32 UTC
Going to close this bug, since I've opened a dedicated bug for all of the vulnerabilities. This makes it easier for our tools to track those issues and making sure that all affected codestreams will eventually be fixed.

CVE-2018-14363 bnc#1101566
CVE-2018-14362 bnc#1101567
CVE-2018-14361 bnc#1101568
CVE-2018-14360 bnc#1101569
CVE-2018-14359 bnc#1101570
CVE-2018-14358 bnc#1101571
CVE-2018-14357 bnc#1101573
CVE-2018-14356 bnc#1101576
CVE-2018-14355 bnc#1101577
CVE-2018-14354 bnc#1101578
CVE-2018-14353 bnc#1101581
CVE-2018-14352 bnc#1101582
CVE-2018-14351 bnc#1101583
CVE-2018-14350 bnc#1101588
CVE-2018-14349 bnc#1101589
Comment 7 Karol Babioch 2018-07-18 07:45:55 UTC
See previous comment.
Comment 9 Swamp Workflow Management 2018-07-18 08:50:05 UTC
This is an autogenerated message for OBS integration:
This bug (1101428) was mentioned in
https://build.opensuse.org/request/show/623577 Factory / mutt
Comment 12 Swamp Workflow Management 2018-08-06 13:14:05 UTC
openSUSE-SU-2018:2212-1: An update that solves 16 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1094717,1101428,1101566,1101567,1101568,1101569,1101570,1101571,1101573,1101576,1101577,1101578,1101581,1101582,1101583,1101588,1101589
CVE References: CVE-2014-9116,CVE-2018-14349,CVE-2018-14350,CVE-2018-14351,CVE-2018-14352,CVE-2018-14353,CVE-2018-14354,CVE-2018-14355,CVE-2018-14356,CVE-2018-14357,CVE-2018-14358,CVE-2018-14359,CVE-2018-14360,CVE-2018-14361,CVE-2018-14362,CVE-2018-14363
Sources used:
openSUSE Leap 15.0 (src):    mutt-1.10.1-lp150.2.3.1
Comment 13 Swamp Workflow Management 2019-01-07 15:40:35 UTC
This is an autogenerated message for OBS integration:
This bug (1101428) was mentioned in
https://build.opensuse.org/request/show/663361 42.3 / mutt
Comment 14 Swamp Workflow Management 2019-01-17 17:10:56 UTC
openSUSE-SU-2019:0052-1: An update that solves 16 vulnerabilities and has 6 fixes is now available.

Category: security (important)
Bug References: 1061343,1094717,1101428,1101566,1101567,1101568,1101569,1101570,1101571,1101573,1101576,1101577,1101578,1101581,1101582,1101583,1101588,1101589,1120935,980830,982129,986534
CVE References: CVE-2014-9116,CVE-2018-14349,CVE-2018-14350,CVE-2018-14351,CVE-2018-14352,CVE-2018-14353,CVE-2018-14354,CVE-2018-14355,CVE-2018-14356,CVE-2018-14357,CVE-2018-14358,CVE-2018-14359,CVE-2018-14360,CVE-2018-14361,CVE-2018-14362,CVE-2018-14363
Sources used:
openSUSE Leap 42.3 (src):    mutt-1.10.1-2.5.1
Comment 15 Swamp Workflow Management 2019-05-09 10:09:22 UTC
SUSE-SU-2019:1196-1: An update that solves 16 vulnerabilities and has 5 fixes is now available.

Category: security (important)
Bug References: 1061343,1094717,1101428,1101566,1101567,1101568,1101569,1101570,1101571,1101573,1101576,1101577,1101578,1101581,1101582,1101583,1101588,1101589,980830,982129,986534
CVE References: CVE-2014-9116,CVE-2018-14349,CVE-2018-14350,CVE-2018-14351,CVE-2018-14352,CVE-2018-14353,CVE-2018-14354,CVE-2018-14355,CVE-2018-14356,CVE-2018-14357,CVE-2018-14358,CVE-2018-14359,CVE-2018-14360,CVE-2018-14361,CVE-2018-14362,CVE-2018-14363
Sources used:
SUSE Linux Enterprise Server 12-SP3 (src):    mutt-1.10.1-55.6.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    mutt-1.10.1-55.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.