{"id":"CVE-2018-14357","details":"An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.","modified":"2026-04-02T01:13:15.471123Z","published":"2018-07-17T17:29:00.700Z","related":["MGASA-2018-0447","SUSE-SU-2018:2084-1","SUSE-SU-2018:2085-1","SUSE-SU-2018:2403-1","SUSE-SU-2019:1196-1","openSUSE-SU-2024:11069-1","openSUSE-SU-2024:11079-1"],"references":[{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4277"},{"type":"ADVISORY","url":"http://www.mutt.org/news.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2526"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201810-07"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3719-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3719-3/"},{"type":"ADVISORY","url":"https://neomutt.org/2018/07/16/release"},{"type":"FIX","url":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"},{"type":"FIX","url":"https://gitlab.com/muttmua/mutt/commit/185152818541f5cdc059cbff3f3e8b654fc27c1d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"ed9d7727dc705754871e31cb41420f0ea956495b"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.10.1"}]}},{"type":"GIT","repo":"https://github.com/neomutt/neomutt","events":[{"introduced":"0"},{"fixed":"6a147a62cf39c2a12cf2e96a8a62f378164548fa"},{"fixed":"e52393740334443ae0206cab2d7caef381646725"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"20180716"}]}},{"type":"GIT","repo":"https://gitlab.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"185152818541f5cdc059cbff3f3e8b654fc27c1d"}]}],"versions":["archive/mutt-0-93","archive/mutt-0-94","archive/mutt-0-95-exp","archive/mutt-1-0-stable","archive/mutt-1-2-5-1","archive/mutt-1-2-stable","archive/mutt-1-4-stable","archive/mutt-1-4-stable-NEW_NOICONV","archive/muttintl","archive/old-master","mutt-0-92-10i","mutt-0-92-11i","mutt-0-92-12i-rel","mutt-0-92-13-rel","mutt-0-92-14i-rel","mutt-0-92-9i","mutt-0-93-1i-rel","mutt-0-93-2i-prerel","mutt-0-93-2i-rel","mutt-0-93-unstable","mutt-0-93i-rel","mutt-0-94-10i-rel","mutt-0-94-13-rel","mutt-0-94-14-rel","mutt-0-94-15-rel","mutt-0-94-16i-rel","mutt-0-94-17i-rel","mutt-0-94-18-rel","mutt-0-94-1i-rel","mutt-0-94-2i-rel","mutt-0-94-3i-rel","mutt-0-94-4i-rel","mutt-0-94-5i-rel","mutt-0-94-6i-rel","mutt-0-94-7i-rel","mutt-0-94-8i-rel","mutt-0-94-9i-p1","mutt-0-94-9i-rel","mutt-0-94i-rel","mutt-0-95-2-rel","mutt-0-95-3-rel","mutt-0-95-4-rel","mutt-0-95-6-rel","mutt-0-95-7-rel","mutt-0-95-rel","mutt-0-96-1-rel","mutt-0-96-2-slightly-post-release","mutt-0-96-3-rel","mutt-0-96-4-rel","mutt-0-96-5-rel","mutt-0-96-6-rel","mutt-0-96-7-rel","mutt-0-96-8-rel","mutt-0-96-rel","mutt-1-0-1-rel","mutt-1-0-pre1-rel","mutt-1-0-pre2-rel","mutt-1-0-pre3","mutt-1-0-pre4-rel","mutt-1-0-rel","mutt-1-0-stable-mailcap","mutt-1-0-stable-nomailcap","mutt-1-1-1-1-rel","mutt-1-1-1-2-rel","mutt-1-1-1-rel","mutt-1-1-10-rel","mutt-1-1-11-rel","mutt-1-1-12-rel","mutt-1-1-13-rel","mutt-1-1-14-rel","mutt-1-1-2-rel","mutt-1-1-3-rel","mutt-1-1-4-rel","mutt-1-1-5-rel","mutt-1-1-6-rel","mutt-1-1-7-rel","mutt-1-1-8-rel","mutt-1-1-9-rel","mutt-1-1-rel","mutt-1-10-rel","mutt-1-2-1-rel","mutt-1-2-2-rel","mutt-1-2-3-rel","mutt-1-2-4-rel","mutt-1-2-5-1-rel","mutt-1-2-5-rel","mutt-1-2-rel","mutt-1-3-1-rel","mutt-1-3-10-rel","mutt-1-3-11-rel","mutt-1-3-12-rel","mutt-1-3-13-rel","mutt-1-3-14-rel","mutt-1-3-15-rel","mutt-1-3-16-rel","mutt-1-3-17-rel","mutt-1-3-18-rel","mutt-1-3-19-rel","mutt-1-3-2-rel","mutt-1-3-20-rel","mutt-1-3-21-rel","mutt-1-3-22-1-rel","mutt-1-3-22-rel","mutt-1-3-23-1-rel","mutt-1-3-23-2-rel","mutt-1-3-23-rel","mutt-1-3-24-rel","mutt-1-3-25-rel","mutt-1-3-26-rel","mutt-1-3-27-rel","mutt-1-3-28-rel","mutt-1-3-3-rel","mutt-1-3-4-rel","mutt-1-3-5-rel","mutt-1-3-6-rel","mutt-1-3-7-rel","mutt-1-3-8-rel","mutt-1-3-9-rel","mutt-1-3-99-rel","mutt-1-3-rel","mutt-1-4-1-rel","mutt-1-4-2-1-rel","mutt-1-4-2-2-rel","mutt-1-4-2-3-rel","mutt-1-4-2-rel","mutt-1-4-rel","mutt-1-5-1-rel","mutt-1-5-10-rel","mutt-1-5-11-rel","mutt-1-5-12-rel","mutt-1-5-13-rel","mutt-1-5-14-rel","mutt-1-5-15-rel","mutt-1-5-16-rel","mutt-1-5-17-rel","mutt-1-5-18-rel","mutt-1-5-19-rel","mutt-1-5-2-rel","mutt-1-5-20-rel","mutt-1-5-21-rel","mutt-1-5-22-rel","mutt-1-5-23-rel","mutt-1-5-24-rel","mutt-1-5-3-rel","mutt-1-5-4-rel","mutt-1-5-5-1-rel","mutt-1-5-5-rel","mutt-1-5-6-rel","mutt-1-5-7-rel","mutt-1-5-8-rel","mutt-1-5-9-rel","mutt-1-6-1-rel","mutt-1-6-2-rel","mutt-1-6-rel","mutt-1-7-1-rel","mutt-1-7-2-rel","mutt-1-7-rel","mutt-1-8-1-rel","mutt-1-8-2-rel","mutt-1-8-3-rel","mutt-1-8-rel","mutt-1-9-1-rel","mutt-1-9-2-rel","mutt-1-9-3-rel","mutt-1-9-4-rel","mutt-1-9-5-rel","mutt-1-9-rel","muttintl-0-92-8i","neomutt-20160307","neomutt-20160317","neomutt-20160320","neomutt-20160328","neomutt-20160404","neomutt-20160416","neomutt-20160502","neomutt-20160530","neomutt-20160611","neomutt-20160709","neomutt-20160723","neomutt-20160808","neomutt-20160821","neomutt-20160822","neomutt-20160826","neomutt-20160827","neomutt-20160910","neomutt-20160916","neomutt-20161002","neomutt-20161003","neomutt-20161014","neomutt-20161028","neomutt-20161104","neomutt-20161126","neomutt-20170113","neomutt-20170128","neomutt-20170206","neomutt-20170225","neomutt-20170306","neomutt-20170414","neomutt-20170421","neomutt-20170428","neomutt-20170526","neomutt-20170602","neomutt-20170609","neomutt-20170707","neomutt-20170714","neomutt-20170907","neomutt-20170912","neomutt-20171006","neomutt-20171013","neomutt-20171027","neomutt-20171208","neomutt-20171215","neomutt-20180223","neomutt-20180323","neomutt-20180512","neomutt-20180622","post-type-punning-patch","pre-type-punning-patch"],"database_specific":{"vanir_signatures":[{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["218563899158595001308791628437925633403","227032016281452034997778241664359416981","121955452387884587719052491384722837387","506689728705518440064826266314589397"]},"id":"CVE-2018-14357-0899ff95","target":{"file":"imap/command.c"},"source":"https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["31952942522484068575409883696072157290","150718647487976241170236887315804442895","195246979766333573439280635801526022618","45908318597331465607108365531724022732"]},"id":"CVE-2018-14357-10a917db","target":{"file":"imap/imap_private.h"},"source":"https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d","deprecated":false,"signature_version":"v1"},{"signature_type":"Function","digest":{"function_hash":"25232212404975938392095324741979721523","length":411},"id":"CVE-2018-14357-21eb7944","target":{"file":"imap/util.c","function":"imap_quote_string"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Function","digest":{"function_hash":"54145826516367523844483083921749081584","length":1020},"id":"CVE-2018-14357-3ef2ade0","target":{"file":"imap/auth_login.c","function":"imap_auth_login"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["40059947202003753882794158162630602032","33957418988982031953252871012599315498","14440449832509296460349422180754625881","328550919031994469811580118784132661353"]},"id":"CVE-2018-14357-50f6d5c8","target":{"file":"imap/imap_private.h"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Function","digest":{"function_hash":"228645823018358539514830665902340320393","length":1124},"id":"CVE-2018-14357-59e01704","target":{"file":"imap/command.c","function":"cmd_parse_lsub"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["38275816934835526550139553849663291777","84668977590220873947543140367782392958","272858250823638590734560816738299859458","197331919126694590783117091847939465809","51941361508920648674779441686070670670","194784290279722335795310118604540377499","212420238482727122243216053129668158301","1736061709541927672894172239778923985","97656863909256314289154183120921480207"]},"id":"CVE-2018-14357-62f6c109","target":{"file":"imap/imap.c"},"source":"https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d","deprecated":false,"signature_version":"v1"},{"signature_type":"Function","digest":{"function_hash":"42665550993922102829047012000358714254","length":1439},"id":"CVE-2018-14357-632ede0e","target":{"file":"imap/imap.c","function":"imap_subscribe"},"source":"https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d","deprecated":false,"signature_version":"v1"},{"signature_type":"Function","digest":{"function_hash":"291529779614175762299804966543294971833","length":1785},"id":"CVE-2018-14357-9d1cab05","target":{"file":"imap/imap.c","function":"compile_search"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["290371799708502961206057772632536943091","18535148220572482381713302160943144077","112636599605313640367218014315756889488","155916374119256125216399603904507973822","286118849534253534257468740577239685662","223538712502296627128770503380775501472","249381483255595934883473801724589076338","30161640952715552746956554296785670435","289232574174694656604675269615861344305","237931762224159757948265487617735571981","160280846770068004037930240257375366972","330590195154125417232703690332110355416","240245407675162988225333038990089718837","126289386742731416981764470008903900873","265881874339859241327523780800113630105","318222868274895948634329615183172928997","189972794556539960752497622871393179339","59123788372805168635155429699586443622","270760812293094337621602240599557051224","204593421235506536873346765773146028705","21128045233681405009357938533431397937","33551005496761524339892479546261424258"]},"id":"CVE-2018-14357-a4b01ba9","target":{"file":"imap/imap.c"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Function","digest":{"function_hash":"246102907976701583778681406207369390654","length":417},"id":"CVE-2018-14357-a951c6d9","target":{"file":"imap/util.c","function":"imap_quote_string"},"source":"https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d","deprecated":false,"signature_version":"v1"},{"signature_type":"Function","digest":{"function_hash":"307367527101721205064864789758691292796","length":208},"id":"CVE-2018-14357-aba3a888","target":{"file":"imap/util.c","function":"imap_munge_mbox_name"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["229097236898046633024934805433464608349","83602381607473313393815366418147480894","19095377894295592758775701765302495655","176494269792467988790647947745744230920","203644126986609072164389678235740350197","133503302104114886261060629320855893432","82663813847307772799785084971472340363","302829093608743047112308803954531093411","155024479240875832356848830543203950212","22431226980439760116591360907198255704","82123232775065497543890611821024729842","55123122238136819455069850209539057260","319011740409708478183254388973645564560"]},"id":"CVE-2018-14357-cc57081f","target":{"file":"imap/util.c"},"source":"https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["66137756997161504403941217310727372939","310724314558957576833016873785582727811","19095377894295592758775701765302495655","151220952131806283612168267188891647283","135727516109020326077663382957561960938","111392465137362549631186206197069015454","72503969521256924378459959459631535089","133567269710818315285880532153331164207","335229863770071323446310299064130419504","91241925715385398596810934857741489207"]},"id":"CVE-2018-14357-da296675","target":{"file":"imap/util.c"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["132748155327204630174065284245821983324","40563222551239612949093301883425487716","121955452387884587719052491384722837387","151693653993940274130361879860361198131"]},"id":"CVE-2018-14357-e8be0a36","target":{"file":"imap/command.c"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["30679469574901647276382938894779000438","32555205313492347667504547345303343458","153293687321224632157823591860082995634","102068395844681187141800602681383507130","330017860411233662183258026172732541333"]},"id":"CVE-2018-14357-faa9f54a","target":{"file":"imap/auth_login.c"},"source":"https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725","deprecated":false,"signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14357.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"14.04"}]},{"events":[{"introduced":"0"},{"last_affected":"16.04"}]},{"events":[{"introduced":"0"},{"last_affected":"18.04"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.7"}]},{"events":[{"introduced":"0"},{"last_affected":"7.5"}]},{"events":[{"introduced":"0"},{"last_affected":"7.6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.7"}]},{"events":[{"introduced":"0"},{"last_affected":"7.6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.7"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}