CVE-2014-9116: Debian Linux

Medium severity, CVSS 5.0. EPSS: 9.7% chance of exploitation in the next 30 days.

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Mageia Mageia: version 4.0 only
  • Mutt Mutt: version 1.5.23 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Suse Linux Enterprise Server: version 12 only

Published 2014-12-02. Last modified 2026-06-17.