CVE-2014-9116: Debian Linux
Medium severity, CVSS 5.0. EPSS: 9.7% chance of exploitation in the next 30 days.
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
Affected products
- Debian Debian Linux: version 7.0 only
- Mageia Mageia: version 4.0 only
- Mutt Mutt: version 1.5.23 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Suse Linux Enterprise Server: version 12 only
Published 2014-12-02. Last modified 2026-06-17.