{"id":"CVE-2018-14362","details":"An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.","modified":"2026-04-11T19:05:37.894528Z","published":"2018-07-17T17:29:00.980Z","related":["MGASA-2018-0447","SUSE-SU-2018:2084-1","SUSE-SU-2018:2085-1","SUSE-SU-2018:2403-1","SUSE-SU-2019:1196-1","openSUSE-SU-2024:11069-1","openSUSE-SU-2024:11079-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"16.04"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"},{"extracted_events":[{"last_affected":"8.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"6.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"6.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.6"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.7"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.5"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.6"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.7"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server_eus:7.7:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.6"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.7"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"6.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"7.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"}]},"references":[{"type":"ADVISORY","url":"http://www.mutt.org/news.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2526"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/08/msg00001.html"},{"type":"ADVISORY","url":"https://neomutt.org/2018/07/16/release"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201810-07"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3719-3/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4277"},{"type":"FIX","url":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e"},{"type":"FIX","url":"https://gitlab.com/muttmua/mutt/commit/6aed28b40a0410ec47d40c8c7296d8d10bae7576"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"ed9d7727dc705754871e31cb41420f0ea956495b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.10.1"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:*"}}],"versions":["mutt-0-92-10i","mutt-0-92-11i","mutt-0-92-9i","mutt-0-93-unstable","mutt-0-94-10i-rel","mutt-0-94-13-rel","mutt-0-94-14-rel","mutt-0-94-15-rel","mutt-0-94-16i-rel","mutt-0-94-17i-rel","mutt-0-94-18-rel","mutt-0-94-5i-rel","mutt-0-94-6i-rel","mutt-0-94-7i-rel","mutt-0-94-8i-rel","mutt-0-94-9i-p1","mutt-0-94-9i-rel","mutt-0-95-rel","mutt-0-96-1-rel","mutt-0-96-2-slightly-post-release","mutt-0-96-3-rel","mutt-0-96-4-rel","mutt-0-96-5-rel","mutt-0-96-6-rel","mutt-0-96-7-rel","mutt-0-96-8-rel","mutt-0-96-rel","mutt-1-1-1-1-rel","mutt-1-1-1-2-rel","mutt-1-1-1-rel","mutt-1-1-10-rel","mutt-1-1-11-rel","mutt-1-1-12-rel","mutt-1-1-13-rel","mutt-1-1-14-rel","mutt-1-1-2-rel","mutt-1-1-3-rel","mutt-1-1-4-rel","mutt-1-1-5-rel","mutt-1-1-6-rel","mutt-1-1-7-rel","mutt-1-1-8-rel","mutt-1-1-9-rel","mutt-1-1-rel","mutt-1-10-rel","mutt-1-3-1-rel","mutt-1-3-10-rel","mutt-1-3-11-rel","mutt-1-3-12-rel","mutt-1-3-13-rel","mutt-1-3-14-rel","mutt-1-3-15-rel","mutt-1-3-16-rel","mutt-1-3-17-rel","mutt-1-3-18-rel","mutt-1-3-19-rel","mutt-1-3-2-rel","mutt-1-3-20-rel","mutt-1-3-21-rel","mutt-1-3-22-1-rel","mutt-1-3-22-rel","mutt-1-3-23-1-rel","mutt-1-3-23-2-rel","mutt-1-3-23-rel","mutt-1-3-24-rel","mutt-1-3-25-rel","mutt-1-3-26-rel","mutt-1-3-27-rel","mutt-1-3-3-rel","mutt-1-3-4-rel","mutt-1-3-5-rel","mutt-1-3-6-rel","mutt-1-3-7-rel","mutt-1-3-8-rel","mutt-1-3-9-rel","mutt-1-3-rel","mutt-1-5-1-rel","mutt-1-5-15-rel","mutt-1-5-16-rel","mutt-1-5-17-rel","mutt-1-5-18-rel","mutt-1-5-19-rel","mutt-1-5-2-rel","mutt-1-5-20-rel","mutt-1-5-21-rel","mutt-1-5-22-rel","mutt-1-5-24-rel","mutt-1-5-3-rel","mutt-1-5-4-rel","mutt-1-5-5-1-rel","mutt-1-5-5-rel","mutt-1-5-6-rel","mutt-1-6-rel","mutt-1-7-rel","mutt-1-8-rel","mutt-1-9-rel","post-type-punning-patch","pre-type-punning-patch"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14362.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/neomutt/neomutt","events":[{"introduced":"0"},{"fixed":"6a147a62cf39c2a12cf2e96a8a62f378164548fa"},{"fixed":"9bfab35522301794483f8f9ed60820bdec9be59e"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"20180716"}],"source":["CPE_FIELD","REFERENCES"],"cpe":"cpe:2.3:a:neomutt:neomutt:*:*:*:*:*:*:*:*"}}],"versions":["neomutt-20160822","neomutt-20160827","neomutt-20160910","neomutt-20160916","neomutt-20161002","neomutt-20161003","neomutt-20161014","neomutt-20161028","neomutt-20161104","neomutt-20161126","neomutt-20170113","neomutt-20170128","neomutt-20170206","neomutt-20170225","neomutt-20170306","neomutt-20170414","neomutt-20170421","neomutt-20170428","neomutt-20170526","neomutt-20170602","neomutt-20170609","neomutt-20170707","neomutt-20170714","neomutt-20170907","neomutt-20170912","neomutt-20171006","neomutt-20171013","neomutt-20171027","neomutt-20171208","neomutt-20171215","neomutt-20180223","neomutt-20180323","neomutt-20180512","neomutt-20180622"],"database_specific":{"vanir_signatures_modified":"2026-04-11T19:05:37Z","source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14362.json","vanir_signatures":[{"signature_type":"Line","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"threshold":0.9,"line_hashes":["166461457871203343767825428571992619843","332801287067323168050430816170670082991","271786472213938683788850057094204643412","119372439653162492663372824806615850337"]},"id":"CVE-2018-14362-5032a5cc","target":{"file":"newsrc.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"length":137,"function_hash":"267537665779261270121660410598778019730"},"id":"CVE-2018-14362-7c96e5e9","target":{"function":"nntp_hcache_namer","file":"newsrc.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Line","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"threshold":0.9,"line_hashes":["282507869725829356368754754288309731924","180075208061962054958382423698787589478","325390537779811331403578311429992453917","40849553194821509632949074050468769859","139842194387533044031811617629497364218","155050040835949172408810526580165649552","136377786910619544328349675424106556833","151860417053105295748988167916222166622","244086138280538416743903398152755732605","332873696842681422891121565529699034939","236007473157134103291937908027325601442","216939413199658701745639496112987145005","324706117862882001673612538146887821301","57129907368067683541711472898614270563","213551591269061358836562623901559679350","152837113381736160920589610252144188990","141585947957200433890708682389411167554","5340409753338793195453880600907208224","241370935965336750474995126612698116846","51823177502555382073407727853414073788","82051695059155998028808786658533210318","122795335888784005275271044672923481284","222778029668092806927494490481893861537","224596775040337544067511760021919277960","221925278420521875570561763670544009873","310573466833311325665692755462274655651","35115817430826594319918924333839638986"]},"id":"CVE-2018-14362-7ee6e997","target":{"file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"length":1605,"function_hash":"221900545852017990172313032652197004192"},"id":"CVE-2018-14362-8f9282b8","target":{"function":"pop_sync_mailbox","file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"length":3017,"function_hash":"317257631665400846064623998635648083237"},"id":"CVE-2018-14362-dc6726c2","target":{"function":"pop_fetch_headers","file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"length":502,"function_hash":"126506414352260493509523767341186245450"},"id":"CVE-2018-14362-e1053d8a","target":{"function":"msg_cache_check","file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e","digest":{"length":2597,"function_hash":"221749324668458347741321909465042818204"},"id":"CVE-2018-14362-ee32bb20","target":{"function":"pop_fetch_message","file":"pop.c"},"deprecated":false,"signature_version":"v1"}]}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/muttmua/mutt","events":[{"introduced":"0"},{"fixed":"6aed28b40a0410ec47d40c8c7296d8d10bae7576"}],"database_specific":{"source":"REFERENCES"}}],"versions":["mutt-0-92-10i","mutt-0-92-11i","mutt-0-92-9i","mutt-0-93-unstable","mutt-0-94-10i-rel","mutt-0-94-13-rel","mutt-0-94-14-rel","mutt-0-94-15-rel","mutt-0-94-16i-rel","mutt-0-94-17i-rel","mutt-0-94-18-rel","mutt-0-94-5i-rel","mutt-0-94-6i-rel","mutt-0-94-7i-rel","mutt-0-94-8i-rel","mutt-0-94-9i-p1","mutt-0-94-9i-rel","mutt-0-95-rel","mutt-0-96-1-rel","mutt-0-96-2-slightly-post-release","mutt-0-96-3-rel","mutt-0-96-4-rel","mutt-0-96-5-rel","mutt-0-96-6-rel","mutt-0-96-7-rel","mutt-0-96-8-rel","mutt-0-96-rel","mutt-1-1-1-1-rel","mutt-1-1-1-2-rel","mutt-1-1-1-rel","mutt-1-1-10-rel","mutt-1-1-11-rel","mutt-1-1-12-rel","mutt-1-1-13-rel","mutt-1-1-14-rel","mutt-1-1-2-rel","mutt-1-1-3-rel","mutt-1-1-4-rel","mutt-1-1-5-rel","mutt-1-1-6-rel","mutt-1-1-7-rel","mutt-1-1-8-rel","mutt-1-1-9-rel","mutt-1-1-rel","mutt-1-10-rel","mutt-1-3-1-rel","mutt-1-3-10-rel","mutt-1-3-11-rel","mutt-1-3-12-rel","mutt-1-3-13-rel","mutt-1-3-14-rel","mutt-1-3-15-rel","mutt-1-3-16-rel","mutt-1-3-17-rel","mutt-1-3-18-rel","mutt-1-3-19-rel","mutt-1-3-2-rel","mutt-1-3-20-rel","mutt-1-3-21-rel","mutt-1-3-22-1-rel","mutt-1-3-22-rel","mutt-1-3-23-1-rel","mutt-1-3-23-2-rel","mutt-1-3-23-rel","mutt-1-3-24-rel","mutt-1-3-25-rel","mutt-1-3-26-rel","mutt-1-3-27-rel","mutt-1-3-3-rel","mutt-1-3-4-rel","mutt-1-3-5-rel","mutt-1-3-6-rel","mutt-1-3-7-rel","mutt-1-3-8-rel","mutt-1-3-9-rel","mutt-1-3-rel","mutt-1-5-1-rel","mutt-1-5-15-rel","mutt-1-5-16-rel","mutt-1-5-17-rel","mutt-1-5-18-rel","mutt-1-5-19-rel","mutt-1-5-2-rel","mutt-1-5-20-rel","mutt-1-5-21-rel","mutt-1-5-22-rel","mutt-1-5-24-rel","mutt-1-5-3-rel","mutt-1-5-4-rel","mutt-1-5-5-1-rel","mutt-1-5-5-rel","mutt-1-5-6-rel","mutt-1-6-rel","mutt-1-7-rel","mutt-1-8-rel","mutt-1-9-rel","post-type-punning-patch","pre-type-punning-patch"],"database_specific":{"vanir_signatures_modified":"2026-04-11T19:05:37Z","source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-14362.json","vanir_signatures":[{"signature_type":"Function","source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","digest":{"length":1554,"function_hash":"203877282032082513856670457410106984505"},"id":"CVE-2018-14362-220a3e57","target":{"function":"pop_sync_mailbox","file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","digest":{"length":508,"function_hash":"325500082941333257680736014199074461078"},"id":"CVE-2018-14362-49a43789","target":{"function":"msg_cache_check","file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Line","source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","digest":{"threshold":0.9,"line_hashes":["249015905104921783268118379981716813190","180075208061962054958382423698787589478","325390537779811331403578311429992453917","278699521853201390138733764370018106823","136146737738893881373200863103551512706","37946969253956364904725322594086040643","136377786910619544328349675424106556833","252327019854101608580927746545791717975","311774669800139807448699864180319932977","312391031714537274799489084210941021847","65533333092715524251554559761039476142","319048243970272962809421998665251142787","15399704111583966608829171321511557541","139248657884988144472504769782390882235","100776044121495972102910698871361049635","233062047643696112113804803750618361816","255431875871928149974607115155767126849","141430068407181609594324196064843873604","272757196427394987088838092283140012902","51823177502555382073407727853414073788","82051695059155998028808786658533210318","122795335888784005275271044672923481284","222778029668092806927494490481893861537","178986409078730298952473038896566632911","118940702271776095458127372552951708946","253565662786306008209989016921826687734","67385587830157418889556558718074387589"]},"id":"CVE-2018-14362-6549483d","target":{"file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","digest":{"length":2980,"function_hash":"299808168449394784185784048087150085601"},"id":"CVE-2018-14362-6f134f7b","target":{"function":"pop_fetch_headers","file":"pop.c"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","source":"https://gitlab.com/muttmua/mutt@6aed28b40a0410ec47d40c8c7296d8d10bae7576","digest":{"length":2632,"function_hash":"227203994769922844282177250937303926350"},"id":"CVE-2018-14362-f506d620","target":{"function":"pop_fetch_message","file":"pop.c"},"deprecated":false,"signature_version":"v1"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}