SCIENTIFIC-LINUX-ERRATA Archives

March 2014

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 17 Mar 2014 18:51:33 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (26 lines)
Synopsis:          Important: mutt security update
Advisory ID:       SLSA-2014:0304-1
Issue Date:        2014-03-17
CVE Numbers:       CVE-2014-0467
--

A heap-based buffer overflow flaw was found in the way mutt processed
certain email headers. A remote attacker could use this flaw to send an
email with specially crafted headers that, when processed, could cause
mutt to crash or, potentially, execute arbitrary code with the permissions
of the user running mutt. (CVE-2014-0467)

All running instances of mutt must be restarted for this update to take
effect.
--

SL6
  x86_64
    mutt-1.5.20-4.20091214hg736b6a.el6_5.x86_64.rpm
    mutt-debuginfo-1.5.20-4.20091214hg736b6a.el6_5.x86_64.rpm
  i386
    mutt-1.5.20-4.20091214hg736b6a.el6_5.i686.rpm
    mutt-debuginfo-1.5.20-4.20091214hg736b6a.el6_5.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2