{"id":"CVE-2018-14362","details":"An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.","modified":"2026-04-11T12:27:31.770824Z","published":"2018-07-17T17:29:00.980Z","related":["MGASA-2018-0447","SUSE-SU-2018:2084-1","SUSE-SU-2018:2085-1","SUSE-SU-2018:2403-1","SUSE-SU-2019:1196-1","openSUSE-SU-2024:11069-1","openSUSE-SU-2024:11079-1"],"references":[{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201810-07"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2526"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html"},{"type":"ADVISORY","url":"https://neomutt.org/2018/07/16/release"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3719-3/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4277"},{"type":"ADVISORY","url":"http://www.mutt.org/news.html"},{"type":"FIX","url":"https://gitlab.com/muttmua/mutt/commit/6aed28b40a0410ec47d40c8c7296d8d10bae7576"},{"type":"FIX","url":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"ed9d7727dc705754871e31cb41420f0ea956495b"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.10.1"}]}},{"type":"GIT","repo":"https://github.com/neomutt/neomutt","events":[{"introduced":"0"},{"fixed":"6a147a62cf39c2a12cf2e96a8a62f378164548fa"},{"fixed":"9bfab35522301794483f8f9ed60820bdec9be59e"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"20180716"}]}},{"type":"GIT","repo":"https://gitlab.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"6aed28b40a0410ec47d40c8c7296d8d10bae7576"}]}],"versions":["mutt-0-92-10i","mutt-0-92-11i","mutt-0-92-9i","mutt-0-93-unstable","mutt-0-94-10i-rel","mutt-0-94-13-rel","mutt-0-94-14-rel","mutt-0-94-15-rel","mutt-0-94-16i-rel","mutt-0-94-17i-rel","mutt-0-94-18-rel","mutt-0-94-5i-rel","mutt-0-94-6i-rel","mutt-0-94-7i-rel","mutt-0-94-8i-rel","mutt-0-94-9i-p1","mutt-0-94-9i-rel","mutt-0-95-rel","mutt-0-96-1-rel","mutt-0-96-2-slightly-post-release","mutt-0-96-3-rel","mutt-0-96-4-rel","mutt-0-96-5-rel","mutt-0-96-6-rel","mutt-0-96-7-rel","mutt-0-96-8-rel","mutt-0-96-rel","mutt-1-1-1-1-rel","mutt-1-1-1-2-rel","mutt-1-1-1-rel","mutt-1-1-10-rel","mutt-1-1-11-rel","mutt-1-1-12-rel","mutt-1-1-13-rel","mutt-1-1-14-rel","mutt-1-1-2-rel","mutt-1-1-3-rel","mutt-1-1-4-rel","mutt-1-1-5-rel","mutt-1-1-6-rel","mutt-1-1-7-rel","mutt-1-1-8-rel","mutt-1-1-9-rel","mutt-1-1-rel","mutt-1-10-rel","mutt-1-3-1-rel","mutt-1-3-10-rel","mutt-1-3-11-rel","mutt-1-3-12-rel","mutt-1-3-13-rel","mutt-1-3-14-rel","mutt-1-3-15-rel","mutt-1-3-16-rel","mutt-1-3-17-rel","mutt-1-3-18-rel","mutt-1-3-19-rel","mutt-1-3-2-rel","mutt-1-3-20-rel","mutt-1-3-21-rel","mutt-1-3-22-1-rel","mutt-1-3-22-rel","mutt-1-3-23-1-rel","mutt-1-3-23-2-rel","mutt-1-3-23-rel","mutt-1-3-24-rel","mutt-1-3-25-rel","mutt-1-3-26-rel","mutt-1-3-27-rel","mutt-1-3-3-rel","mutt-1-3-4-rel","mutt-1-3-5-rel","mutt-1-3-6-rel","mutt-1-3-7-rel","mutt-1-3-8-rel","mutt-1-3-9-rel","mutt-1-3-rel","mutt-1-5-1-rel","mutt-1-5-15-rel","mutt-1-5-16-rel","mutt-1-5-17-rel","mutt-1-5-18-rel","mutt-1-5-19-rel","mutt-1-5-2-rel","mutt-1-5-20-rel","mutt-1-5-21-rel","mutt-1-5-22-rel","mutt-1-5-24-rel","mutt-1-5-3-rel","mutt-1-5-4-rel","mutt-1-5-5-1-rel","mutt-1-5-5-rel","mutt-1-5-6-rel","mutt-1-6-rel","mutt-1-7-rel","mutt-1-8-rel","mutt-1-9-rel","neomutt-20160822","neomutt-20160827","neomutt-20160910","neomutt-20160916","neomutt-20161002","neomutt-20161003","neomutt-20161014","neomutt-20161028","neomutt-20161104","neomutt-20161126","neomutt-20170113","neomutt-20170128","neomutt-20170206","neomutt-20170225","neomutt-20170306","neomutt-20170414","neomutt-20170421","neomutt-20170428","neomutt-20170526","neomutt-20170602","neomutt-20170609","neomutt-20170707","neomutt-20170714","neomutt-20170907","neomutt-20170912","neomutt-20171006","neomutt-20171013","neomutt-20171027","neomutt-20171208","neomutt-20171215","neomutt-20180223","neomutt-20180323","neomutt-20180512","neomutt-20180622","post-type-punning-patch","pre-type-punning-patch"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"16.04"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.7"}]},{"events":[{"introduced":"0"},{"last_affected":"7.5"}]},{"events":[{"introduced":"0"},{"last_affected":"7.6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.7"}]},{"events":[{"introduced":"0"},{"last_affected":"7.6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.7"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]}],"vanir_signatures_modified":"2026-04-11T12:27:31Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14362.json","vanir_signatures":[{"target":{"file":"pop.c","function":"pop_sync_mailbox"},"source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"203877282032082513856670457410106984505","length":1554},"id":"CVE-2018-14362-220a3e57"},{"target":{"file":"pop.c","function":"msg_cache_check"},"source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"325500082941333257680736014199074461078","length":508},"id":"CVE-2018-14362-49a43789"},{"target":{"file":"newsrc.c"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Line","deprecated":false,"digest":{"line_hashes":["166461457871203343767825428571992619843","332801287067323168050430816170670082991","271786472213938683788850057094204643412","119372439653162492663372824806615850337"],"threshold":0.9},"id":"CVE-2018-14362-5032a5cc"},{"target":{"file":"pop.c"},"source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","signature_version":"v1","signature_type":"Line","deprecated":false,"digest":{"line_hashes":["249015905104921783268118379981716813190","180075208061962054958382423698787589478","325390537779811331403578311429992453917","278699521853201390138733764370018106823","136146737738893881373200863103551512706","37946969253956364904725322594086040643","136377786910619544328349675424106556833","252327019854101608580927746545791717975","311774669800139807448699864180319932977","312391031714537274799489084210941021847","65533333092715524251554559761039476142","319048243970272962809421998665251142787","15399704111583966608829171321511557541","139248657884988144472504769782390882235","100776044121495972102910698871361049635","233062047643696112113804803750618361816","255431875871928149974607115155767126849","141430068407181609594324196064843873604","272757196427394987088838092283140012902","51823177502555382073407727853414073788","82051695059155998028808786658533210318","122795335888784005275271044672923481284","222778029668092806927494490481893861537","178986409078730298952473038896566632911","118940702271776095458127372552951708946","253565662786306008209989016921826687734","67385587830157418889556558718074387589"],"threshold":0.9},"id":"CVE-2018-14362-6549483d"},{"target":{"file":"pop.c","function":"pop_fetch_headers"},"source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"299808168449394784185784048087150085601","length":2980},"id":"CVE-2018-14362-6f134f7b"},{"target":{"file":"newsrc.c","function":"nntp_hcache_namer"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"267537665779261270121660410598778019730","length":137},"id":"CVE-2018-14362-7c96e5e9"},{"target":{"file":"pop.c"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Line","deprecated":false,"digest":{"line_hashes":["282507869725829356368754754288309731924","180075208061962054958382423698787589478","325390537779811331403578311429992453917","40849553194821509632949074050468769859","139842194387533044031811617629497364218","155050040835949172408810526580165649552","136377786910619544328349675424106556833","151860417053105295748988167916222166622","244086138280538416743903398152755732605","332873696842681422891121565529699034939","236007473157134103291937908027325601442","216939413199658701745639496112987145005","324706117862882001673612538146887821301","57129907368067683541711472898614270563","213551591269061358836562623901559679350","152837113381736160920589610252144188990","141585947957200433890708682389411167554","5340409753338793195453880600907208224","241370935965336750474995126612698116846","51823177502555382073407727853414073788","82051695059155998028808786658533210318","122795335888784005275271044672923481284","222778029668092806927494490481893861537","224596775040337544067511760021919277960","221925278420521875570561763670544009873","310573466833311325665692755462274655651","35115817430826594319918924333839638986"],"threshold":0.9},"id":"CVE-2018-14362-7ee6e997"},{"target":{"file":"pop.c","function":"pop_sync_mailbox"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"221900545852017990172313032652197004192","length":1605},"id":"CVE-2018-14362-8f9282b8"},{"target":{"file":"pop.c","function":"pop_fetch_headers"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"317257631665400846064623998635648083237","length":3017},"id":"CVE-2018-14362-dc6726c2"},{"target":{"file":"pop.c","function":"msg_cache_check"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"126506414352260493509523767341186245450","length":502},"id":"CVE-2018-14362-e1053d8a"},{"target":{"file":"pop.c","function":"pop_fetch_message"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"221749324668458347741321909465042818204","length":2597},"id":"CVE-2018-14362-ee32bb20"},{"target":{"file":"pop.c","function":"pop_fetch_message"},"source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","signature_version":"v1","signature_type":"Function","deprecated":false,"digest":{"function_hash":"227203994769922844282177250937303926350","length":2632},"id":"CVE-2018-14362-f506d620"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}