{"id":"CVE-2018-14363","details":"An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.","modified":"2026-04-16T06:18:14.818077117Z","published":"2018-07-17T17:29:01.027Z","related":["SUSE-SU-2018:2084-1","SUSE-SU-2018:2085-1","SUSE-SU-2019:1196-1","openSUSE-SU-2024:11069-1","openSUSE-SU-2024:11079-1"],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html"},{"type":"ADVISORY","url":"https://neomutt.org/2018/07/16/release"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4277"},{"type":"FIX","url":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/neomutt/neomutt","events":[{"introduced":"0"},{"fixed":"6a147a62cf39c2a12cf2e96a8a62f378164548fa"},{"fixed":"9bfab35522301794483f8f9ed60820bdec9be59e"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"20180716"}]}}],"versions":["neomutt-20160822","neomutt-20160827","neomutt-20160910","neomutt-20160916","neomutt-20161002","neomutt-20161003","neomutt-20161014","neomutt-20161028","neomutt-20161104","neomutt-20161126","neomutt-20170113","neomutt-20170128","neomutt-20170206","neomutt-20170225","neomutt-20170306","neomutt-20170414","neomutt-20170421","neomutt-20170428","neomutt-20170526","neomutt-20170602","neomutt-20170609","neomutt-20170707","neomutt-20170714","neomutt-20170907","neomutt-20170912","neomutt-20171006","neomutt-20171013","neomutt-20171027","neomutt-20171208","neomutt-20171215","neomutt-20180223","neomutt-20180323","neomutt-20180512","neomutt-20180622"],"database_specific":{"vanir_signatures":[{"deprecated":false,"target":{"file":"newsrc.c"},"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["166461457871203343767825428571992619843","332801287067323168050430816170670082991","271786472213938683788850057094204643412","119372439653162492663372824806615850337"]},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_type":"Line","id":"CVE-2018-14363-5032a5cc"},{"deprecated":false,"target":{"file":"newsrc.c","function":"nntp_hcache_namer"},"signature_version":"v1","digest":{"length":137,"function_hash":"267537665779261270121660410598778019730"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_type":"Function","id":"CVE-2018-14363-7c96e5e9"},{"id":"CVE-2018-14363-7ee6e997","target":{"file":"pop.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["282507869725829356368754754288309731924","180075208061962054958382423698787589478","325390537779811331403578311429992453917","40849553194821509632949074050468769859","139842194387533044031811617629497364218","155050040835949172408810526580165649552","136377786910619544328349675424106556833","151860417053105295748988167916222166622","244086138280538416743903398152755732605","332873696842681422891121565529699034939","236007473157134103291937908027325601442","216939413199658701745639496112987145005","324706117862882001673612538146887821301","57129907368067683541711472898614270563","213551591269061358836562623901559679350","152837113381736160920589610252144188990","141585947957200433890708682389411167554","5340409753338793195453880600907208224","241370935965336750474995126612698116846","51823177502555382073407727853414073788","82051695059155998028808786658533210318","122795335888784005275271044672923481284","222778029668092806927494490481893861537","224596775040337544067511760021919277960","221925278420521875570561763670544009873","310573466833311325665692755462274655651","35115817430826594319918924333839638986"]},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_version":"v1","signature_type":"Line"},{"target":{"file":"pop.c","function":"pop_sync_mailbox"},"signature_type":"Function","signature_version":"v1","id":"CVE-2018-14363-8f9282b8","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"length":1605,"function_hash":"221900545852017990172313032652197004192"},"deprecated":false},{"deprecated":false,"target":{"file":"pop.c","function":"pop_fetch_headers"},"signature_version":"v1","digest":{"length":3017,"function_hash":"317257631665400846064623998635648083237"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_type":"Function","id":"CVE-2018-14363-dc6726c2"},{"id":"CVE-2018-14363-e1053d8a","signature_type":"Function","deprecated":false,"digest":{"length":502,"function_hash":"126506414352260493509523767341186245450"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","target":{"file":"pop.c","function":"msg_cache_check"},"signature_version":"v1"},{"deprecated":false,"target":{"file":"pop.c","function":"pop_fetch_message"},"signature_version":"v1","digest":{"length":2597,"function_hash":"221749324668458347741321909465042818204"},"source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","signature_type":"Function","id":"CVE-2018-14363-ee32bb20"}],"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]}],"vanir_signatures_modified":"2026-04-11T12:27:45Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14363.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}