EulerOS 2.0 SP15 : mutt (EulerOS-SA-2026-2898)

low Nessus Plugin ID 332940

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the mutt packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.(CVE-2026-43860)

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.(CVE-2026-43863)

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.(CVE-2026-43864)

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.(CVE-2026-43859)

mutt before 2.3.2 does not check for '\0' in url_pct_decode.(CVE-2026-43861)

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.(CVE-2026-43862)

Tenable has extracted the preceding description block directly from the EulerOS mutt security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected mutt packages.

See Also

http://www.nessus.org/u?1706c4bb

Plugin Details

Severity: Low

ID: 332940

File Name: EulerOS_SA-2026-2898.nasl

Version: 1.1

Type: Local

Published: 8/6/2026

Updated: 8/6/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-43861

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-43862

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:mutt-help, p-cpe:/a:huawei:euleros:mutt

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 5/4/2026

Reference Information

CVE: CVE-2026-43859, CVE-2026-43860, CVE-2026-43861, CVE-2026-43862, CVE-2026-43863, CVE-2026-43864