CentOS 6 / 7 : mutt (CESA-2018:2526)
High Nessus Plugin ID 112022
SynopsisThe remote CentOS host is missing a security update.
DescriptionAn update for mutt is now available for Red Hat Enterprise Linux 6 and
Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security
impact of Important. A Common Vulnerability Scoring System (CVSS) base
score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.
Mutt is a low resource, highly configurable, text-based MIME e-mail
client. Mutt supports most e-mail storing formats, such as mbox and
Maildir, as well as most protocols, including POP3 and IMAP.
Security Fix(es) :
* mutt: Remote code injection vulnerability to an IMAP mailbox
* mutt: Remote Code Execution via backquote characters
* mutt: POP body caching path traversal vulnerability (CVE-2018-14362)
For more details about the security issue(s), including the impact, a
CVSS score, and other related information, refer to the CVE page(s)
listed in the References section.
SolutionUpdate the affected mutt package.