CVE-2022-1328

Name
CVE-2022-1328
Description
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.com/muttmua/mutt/-/commit/e5ed080c00e59701ca62ef9b2a6d2612ebf765a5
MISC https://gitlab.com/muttmua/mutt/-/issues/404
CONFIRM https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1328.json
MLIST http://www.openwall.com/lists/oss-security/2022/04/14/3
Mailing List https://lists.debian.org/debian-lts-announce/2022/05/msg00010.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:* mutt >= 0.94.13 < 2.2.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mutt edge-community 3.2.3-r0 None fixed
mutt edge-community 2.2.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mutt edge-community 2.0.4-r1 None possibly vulnerable
mutt edge-community 2.0.2-r0 None possibly vulnerable
mutt edge-community 1.14.4-r0 None possibly vulnerable
mutt 3.22-community 2.2.3-r0 None fixed
mutt 3.22-community 2.0.4-r1 None possibly vulnerable
mutt 3.22-community 2.0.2-r0 None possibly vulnerable
mutt 3.22-community 1.14.4-r0 None possibly vulnerable
mutt 3.21-community 2.2.3-r0 None fixed
mutt 3.20-community 2.2.3-r0 None fixed
mutt 3.19-community 2.2.3-r0 None fixed
mutt 3.18-community 2.2.3-r0 None fixed
mutt 3.17-community 2.2.3-r0 None fixed