Bugzilla – Bug 1198518
VUL-0: CVE-2022-1328: mutt: buffer overflow in uudecoder
Last modified: 2022-04-29 19:18:35 UTC
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1328 https://seclists.org/oss-sec/2022/q2/44 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1328 https://gitlab.com/muttmua/mutt/-/issues/404 https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1328.json https://gitlab.com/muttmua/mutt/-/commit/e5ed080c00e59701ca62ef9b2a6d2612ebf765a5
Affected packages: - SUSE:SLE-11:Update/mutt 1.5.17 - SUSE:SLE-12:Update/mutt 1.10.1 - SUSE:SLE-15:Update/mutt 1.10.1 - openSUSE:Factory/mutt 2.1.5 Upstream fix: https://gitlab.com/muttmua/mutt/-/commit/e5ed080c00e59701ca62ef9b2a6d2612ebf765a5
This is an autogenerated message for OBS integration: This bug (1198518) was mentioned in https://build.opensuse.org/request/show/970760 Factory / mutt
SUSE-SU-2022:1376-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1198518 CVE References: CVE-2022-1328 JIRA References: Sources used: openSUSE Leap 15.4 (src): mutt-1.10.1-150000.3.23.1 openSUSE Leap 15.3 (src): mutt-1.10.1-150000.3.23.1 SUSE Linux Enterprise Realtime Extension 15-SP2 (src): mutt-1.10.1-150000.3.23.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): mutt-1.10.1-150000.3.23.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): mutt-1.10.1-150000.3.23.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:1478-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1198518 CVE References: CVE-2022-1328 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP5 (src): mutt-1.10.1-55.27.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.