VDB
CVE-2004-0078
CVE-2004-0078
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.
EPSS 5.43% · 92.1th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.43%
92.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mutt | mutt | 1.2.5.5, 1.2.1, 1.2.5 |
| n/a | n/a | n/a |
Timeline
- Mar 3, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- mutt-index-menu-bo(15134) vdb
- 20040309 [OpenPKG-SA-2004.005] OpenPKG Security Advisory (mutt) mailing-list
- MDKSA-2004:010 vendor-advisory
- SSA:2004-043 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0078 advisory
- http://marc.info/?l=bugtraq&m=107651677817933&w=2 url
- http://www.securityfocus.com/bid/9641 url
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt technical
- http://bugs.debian.org/126336 technical
- http://marc.info/?l=bugtraq&m=107696262905039&w=2 technical
- http://www.osvdb.org/3918 technical
- http://www.redhat.com/support/errata/RHSA-2004-050.html patch
- http://www.redhat.com/support/errata/RHSA-2004-051.html patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A811 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A838 technical