Mutt UTF-7 Internationalized Remote Folder Buffer Overrun Vulnerability

BID:7120

Info

Mutt UTF-7 Internationalized Remote Folder Buffer Overrun Vulnerability

Bugtraq ID: 7120
Class: Boundary Condition Error
CVE: CVE-2003-0140
Remote: Yes
Local: No
Published: Mar 17 2003 12:00AM
Updated: Jul 11 2009 09:06PM
Credit: Discovered by Diego Kelyacoubian, Javier Kohen, Alberto Solino, and Juan Vera of Core Security Technologies.
Vulnerable: Redhat Linux Advanced Work Station 2.1
Redhat Enterprise Linux WS 2.1
Redhat Enterprise Linux ES 2.1
Redhat Enterprise Linux AS 2.1
Mutt Mutt 1.5.3
Mutt Mutt 1.4 .0
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ Mandriva Linux Mandrake 9.0
+ Netwosix Netwosix Linux 1.0
+ OpenPKG OpenPKG 1.2
+ OpenPKG OpenPKG 1.1
+ OpenPKG OpenPKG Current
+ Redhat Linux 8.0 i686
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0
+ SuSE Linux 8.1
Mutt Mutt 1.3.28
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
Mutt Mutt 1.3.27
+ SuSE Linux 8.0 i386
+ SuSE Linux 8.0
Mutt Mutt 1.3.25
Mutt Mutt 1.3.24
Mutt Mutt 1.3.22
+ SuSE Linux 7.3 sparc
+ SuSE Linux 7.3 ppc
+ SuSE Linux 7.3 i386
+ SuSE Linux 7.3
Mutt Mutt 1.3.17
Mutt Mutt 1.3.16
+ SuSE Linux 7.2 i386
+ SuSE Linux 7.2
Mutt Mutt 1.3.12
+ SuSE Linux 7.1 x86
+ SuSE Linux 7.1 sparc
+ SuSE Linux 7.1 ppc
+ SuSE Linux 7.1 alpha
GNOME Balsa 1.2.4
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Redhat Linux 8.0 i686
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0
+ Redhat Linux 7.3 i686
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3
+ Sun Linux 5.0
Not Vulnerable: Mutt Mutt 1.5.4
Mutt Mutt 1.4.1
+ Slackware Linux 9.1
+ Slackware Linux 9.0
+ Slackware Linux 8.1
+ Trustix Secure Linux 2.0

Discussion

Mutt UTF-7 Internationalized Remote Folder Buffer Overrun Vulnerability

It has been reported that Mutt does not properly handle remote internationalized folders. Because of this, it is possible for a malicious server to launch an attack that could result in the execution of code as the mutt user.

Exploit / POC

Mutt UTF-7 Internationalized Remote Folder Buffer Overrun Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Mutt UTF-7 Internationalized Remote Folder Buffer Overrun Vulnerability

Solution:
Conectiva has released an additional advisory CLA-2003:635 that contains fixes to address this issue in Balsa.

Users are advised to upgrade to version 1.4.1 (stable). The patched unstable version is 1.5.4.

OpenPKG has made fixed versions available, and released advisory OpenPKG-SA-2003.025 to address this issue.

Slackware has released fixes for this issue. Users are advised to upgrade to mutt-1.4.1i.

Gentoo Linux has addressed this issue in advisory 200303-19. Affected users have been advised to issue the following commands to upgrade the vulnerable package:

emerge sync
emerge mutt
emerge clean

Red Hat Linux has released an advisory (RHSA-2003:109-03). Information about obtaining and applying fixes are available in the referenced advisory.

Conectiva has released advisory CLA-2003:626 to address this issue. An additional advisory has been released (CLA-2003:630) which contains fixes which address this issue in Balsa.

Gentoo Linux has released a new advisory. Users who have installed net-mail/balsa are advised to upgrade to balsa-2.0.10 by issuing the following commands:

emerge sync
emerge balsa
emerge clean

Red Hat has also released an advisory (RHSA-2003:111-08) which contains upgrade details for Enterprise distributions, which are available through the Red Hat Network.


GNOME Balsa 1.2.4

Mutt Mutt 1.3.12

Mutt Mutt 1.3.16

Mutt Mutt 1.3.17

Mutt Mutt 1.3.22

Mutt Mutt 1.3.24

Mutt Mutt 1.3.25

Mutt Mutt 1.3.27

Mutt Mutt 1.3.28

Mutt Mutt 1.4 .0

Mutt Mutt 1.5.3

References

Mutt UTF-7 Internationalized Remote Folder Buffer Overrun Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report