{"id":"CVE-2018-14353","details":"An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.","modified":"2026-05-18T15:27:24.931747Z","published":"2018-07-17T17:29:00.467Z","related":["SUSE-SU-2018:2084-1","SUSE-SU-2018:2085-1","SUSE-SU-2018:2403-1","SUSE-SU-2019:1196-1","openSUSE-SU-2024:11069-1","openSUSE-SU-2024:11079-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_FIELD","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"],"extracted_events":[{"last_affected":"14.04"},{"last_affected":"16.04"},{"last_affected":"18.04"}]},{"source":"CPE_FIELD","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0"},{"last_affected":"9.0"}]}]},"references":[{"type":"ADVISORY","url":"http://www.mutt.org/news.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html"},{"type":"ADVISORY","url":"https://neomutt.org/2018/07/16/release"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201810-07"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3719-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3719-3/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4277"},{"type":"FIX","url":"https://github.com/neomutt/neomutt/commit/65d64a5b60a4a3883f2cd799d92c6091d8854f23"},{"type":"FIX","url":"https://gitlab.com/muttmua/mutt/commit/e0131852c6059107939893016c8ff56b6e42865d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"ed9d7727dc705754871e31cb41420f0ea956495b"}],"database_specific":{"source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"1.10.1"}],"cpe":"cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:*"}}],"versions":["mutt-1-10-rel","mutt-1-9-rel","mutt-1-8-rel","mutt-1-7-rel","mutt-1-6-rel","mutt-1-5-24-rel","mutt-1-5-22-rel","mutt-1-5-21-rel","mutt-1-5-20-rel","mutt-1-5-19-rel","mutt-1-5-18-rel","mutt-1-5-17-rel","mutt-1-5-16-rel","mutt-1-5-15-rel","mutt-1-5-6-rel","mutt-1-5-5-1-rel","mutt-1-5-5-rel","post-type-punning-patch","pre-type-punning-patch","mutt-1-5-4-rel","mutt-1-5-3-rel","mutt-1-5-2-rel","mutt-1-5-1-rel","mutt-1-3-27-rel","mutt-1-3-26-rel","mutt-1-3-25-rel","mutt-1-3-24-rel","mutt-1-3-23-2-rel","mutt-1-3-23-1-rel","mutt-1-3-23-rel","mutt-1-3-22-1-rel","mutt-1-3-22-rel","mutt-1-3-21-rel","mutt-1-3-20-rel","mutt-1-3-19-rel","mutt-1-3-18-rel","mutt-1-3-17-rel","mutt-1-3-16-rel","mutt-1-3-15-rel","mutt-1-3-14-rel","mutt-1-3-13-rel","mutt-1-3-12-rel","mutt-1-3-11-rel","mutt-1-3-10-rel","mutt-1-3-9-rel","mutt-1-3-8-rel","mutt-1-3-7-rel","mutt-1-3-6-rel","mutt-1-3-5-rel","mutt-1-3-4-rel","mutt-1-3-3-rel","mutt-1-3-2-rel","mutt-1-3-1-rel","mutt-1-3-rel","mutt-1-1-14-rel","mutt-1-1-13-rel","mutt-1-1-12-rel","mutt-1-1-11-rel","mutt-1-1-10-rel","mutt-1-1-9-rel","mutt-1-1-8-rel","mutt-1-1-7-rel","mutt-1-1-6-rel","mutt-1-1-5-rel","mutt-1-1-4-rel","mutt-1-1-3-rel","mutt-1-1-2-rel","mutt-1-1-1-2-rel","mutt-1-1-1-1-rel","mutt-1-1-1-rel","mutt-1-1-rel","mutt-0-96-8-rel","mutt-0-96-7-rel","mutt-0-96-6-rel","mutt-0-96-5-rel","mutt-0-96-4-rel","mutt-0-96-3-rel","mutt-0-96-2-slightly-post-release","mutt-0-96-1-rel","mutt-0-96-rel","mutt-0-95-rel","mutt-0-94-18-rel","mutt-0-94-17i-rel","mutt-0-94-16i-rel","mutt-0-94-15-rel","mutt-0-94-14-rel","mutt-0-94-13-rel","mutt-0-94-10i-rel","mutt-0-94-9i-p1","mutt-0-94-9i-rel","mutt-0-94-8i-rel","mutt-0-94-7i-rel","mutt-0-94-6i-rel","mutt-0-94-5i-rel","mutt-0-93-unstable","mutt-0-92-11i","mutt-0-92-10i","mutt-0-92-9i"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14353.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/neomutt/neomutt","events":[{"introduced":"0"},{"fixed":"6a147a62cf39c2a12cf2e96a8a62f378164548fa"},{"fixed":"65d64a5b60a4a3883f2cd799d92c6091d8854f23"}],"database_specific":{"source":["CPE_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"20180716"}],"cpe":"cpe:2.3:a:neomutt:neomutt:*:*:*:*:*:*:*:*"}}],"versions":["neomutt-20180622","neomutt-20180512","neomutt-20180323","neomutt-20180223","neomutt-20171215","neomutt-20171208","neomutt-20171027","neomutt-20171013","neomutt-20171006","neomutt-20170912","neomutt-20170907","neomutt-20170714","neomutt-20170707","neomutt-20170609","neomutt-20170602","neomutt-20170526","neomutt-20170428","neomutt-20170421","neomutt-20170414","neomutt-20170306","neomutt-20170225","neomutt-20170206","neomutt-20170128","neomutt-20170113","neomutt-20161126","neomutt-20161104","neomutt-20161028","neomutt-20161014","neomutt-20161003","neomutt-20161002","neomutt-20160916","neomutt-20160910","neomutt-20160827","neomutt-20160822"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14353.json","vanir_signatures_modified":"2026-05-18T15:27:24Z","vanir_signatures":[{"signature_version":"v1","deprecated":false,"digest":{"length":441,"function_hash":"295083974743524128245739183431886022538"},"target":{"function":"imap_quote_string","file":"imap/util.c"},"id":"CVE-2018-14353-9045588f","signature_type":"Function","source":"https://github.com/neomutt/neomutt/commit/65d64a5b60a4a3883f2cd799d92c6091d8854f23"},{"signature_version":"v1","deprecated":false,"digest":{"line_hashes":["155024479240875832356848830543203950212","161922765533504463388026272355790387971","73228443791681758382474922922852998804","222731888664080766833588527501041320318","170298567194381714156241404269017013499","153173161433175437829475666550604780854"],"threshold":0.9},"target":{"file":"imap/util.c"},"id":"CVE-2018-14353-c722fa3b","signature_type":"Line","source":"https://github.com/neomutt/neomutt/commit/65d64a5b60a4a3883f2cd799d92c6091d8854f23"}]}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"ed9d7727dc705754871e31cb41420f0ea956495b"},{"fixed":"e0131852c6059107939893016c8ff56b6e42865d"}],"database_specific":{"source":["CPE_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.10.1"}],"cpe":"cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:*"}}],"versions":["mutt-1-10-rel","mutt-1-9-rel","mutt-1-8-rel","mutt-1-7-rel","mutt-1-6-rel","mutt-1-5-24-rel","mutt-1-5-22-rel","mutt-1-5-21-rel","mutt-1-5-20-rel","mutt-1-5-19-rel","mutt-1-5-18-rel","mutt-1-5-17-rel","mutt-1-5-16-rel","mutt-1-5-15-rel","mutt-1-5-6-rel","mutt-1-5-5-1-rel","mutt-1-5-5-rel","post-type-punning-patch","pre-type-punning-patch","mutt-1-5-4-rel","mutt-1-5-3-rel","mutt-1-5-2-rel","mutt-1-5-1-rel","mutt-1-3-27-rel","mutt-1-3-26-rel","mutt-1-3-25-rel","mutt-1-3-24-rel","mutt-1-3-23-2-rel","mutt-1-3-23-1-rel","mutt-1-3-23-rel","mutt-1-3-22-1-rel","mutt-1-3-22-rel","mutt-1-3-21-rel","mutt-1-3-20-rel","mutt-1-3-19-rel","mutt-1-3-18-rel","mutt-1-3-17-rel","mutt-1-3-16-rel","mutt-1-3-15-rel","mutt-1-3-14-rel","mutt-1-3-13-rel","mutt-1-3-12-rel","mutt-1-3-11-rel","mutt-1-3-10-rel","mutt-1-3-9-rel","mutt-1-3-8-rel","mutt-1-3-7-rel","mutt-1-3-6-rel","mutt-1-3-5-rel","mutt-1-3-4-rel","mutt-1-3-3-rel","mutt-1-3-2-rel","mutt-1-3-1-rel","mutt-1-3-rel","mutt-1-1-14-rel","mutt-1-1-13-rel","mutt-1-1-12-rel","mutt-1-1-11-rel","mutt-1-1-10-rel","mutt-1-1-9-rel","mutt-1-1-8-rel","mutt-1-1-7-rel","mutt-1-1-6-rel","mutt-1-1-5-rel","mutt-1-1-4-rel","mutt-1-1-3-rel","mutt-1-1-2-rel","mutt-1-1-1-2-rel","mutt-1-1-1-1-rel","mutt-1-1-1-rel","mutt-1-1-rel","mutt-0-96-8-rel","mutt-0-96-7-rel","mutt-0-96-6-rel","mutt-0-96-5-rel","mutt-0-96-4-rel","mutt-0-96-3-rel","mutt-0-96-2-slightly-post-release","mutt-0-96-1-rel","mutt-0-96-rel","mutt-0-95-rel","mutt-0-94-18-rel","mutt-0-94-17i-rel","mutt-0-94-16i-rel","mutt-0-94-15-rel","mutt-0-94-14-rel","mutt-0-94-13-rel","mutt-0-94-10i-rel","mutt-0-94-9i-p1","mutt-0-94-9i-rel","mutt-0-94-8i-rel","mutt-0-94-7i-rel","mutt-0-94-6i-rel","mutt-0-94-5i-rel","mutt-0-93-unstable","mutt-0-92-11i","mutt-0-92-10i","mutt-0-92-9i"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14353.json","vanir_signatures_modified":"2026-05-18T15:27:24Z","vanir_signatures":[{"signature_version":"v1","deprecated":false,"digest":{"length":410,"function_hash":"40666457325933368291575099386837457356"},"target":{"function":"_imap_quote_string","file":"imap/util.c"},"id":"CVE-2018-14353-d812d2df","signature_type":"Function","source":"https://gitlab.com/muttmua/mutt@e0131852c6059107939893016c8ff56b6e42865d"},{"signature_version":"v1","deprecated":false,"digest":{"line_hashes":["286825986659692381523275984697414304158","116272058307513292299683231627710474868","51651615816479745004171875861077687511","29959305164162731185766895165259995508","328072855443475217845821425628390260381","267919281465194934696159675631347027828","302858303013732373814235239874974723469","1059981929047943784357356626914626281","187464042198075305097852041642751147938","7002288292590039929813425765991714621","179605271331145386996960733985749176276","162105781547520036600742144204354819781","8696559302285177799845044499702199818","153173161433175437829475666550604780854"],"threshold":0.9},"target":{"file":"imap/util.c"},"id":"CVE-2018-14353-e50ea7c2","signature_type":"Line","source":"https://gitlab.com/muttmua/mutt@e0131852c6059107939893016c8ff56b6e42865d"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}