CVE-2023-4874

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-4874
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4874.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4874
Downstream
Related
Published
2023-09-09T14:30:29.741Z
Modified
2025-12-05T00:12:01.464469Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Undefined Behavior for Input to API in Mutt
Details

Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-475"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4874.json"
}
References

Affected packages

Git / github.com/muttmua/mutt

Affected ranges

Type
GIT
Repo
https://github.com/muttmua/mutt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

mutt-0-92-10i
mutt-0-92-11i
mutt-0-92-9i
mutt-0-93-unstable
mutt-0-94-10i-rel
mutt-0-94-13-rel
mutt-0-94-14-rel
mutt-0-94-15-rel
mutt-0-94-16i-rel
mutt-0-94-17i-rel
mutt-0-94-18-rel
mutt-0-94-5i-rel
mutt-0-94-6i-rel
mutt-0-94-7i-rel
mutt-0-94-8i-rel
mutt-0-94-9i-p1
mutt-0-94-9i-rel
mutt-0-95-rel
mutt-0-96-1-rel
mutt-0-96-2-slightly-post-release
mutt-0-96-3-rel
mutt-0-96-4-rel
mutt-0-96-5-rel
mutt-0-96-6-rel
mutt-0-96-7-rel
mutt-0-96-8-rel
mutt-0-96-rel
mutt-1-1-1-1-rel
mutt-1-1-1-2-rel
mutt-1-1-1-rel
mutt-1-1-10-rel
mutt-1-1-11-rel
mutt-1-1-12-rel
mutt-1-1-13-rel
mutt-1-1-14-rel
mutt-1-1-2-rel
mutt-1-1-3-rel
mutt-1-1-4-rel
mutt-1-1-5-rel
mutt-1-1-6-rel
mutt-1-1-7-rel
mutt-1-1-8-rel
mutt-1-1-9-rel
mutt-1-1-rel
mutt-1-10-1-rel
mutt-1-10-rel
mutt-1-11-1-rel
mutt-1-11-2-rel
mutt-1-11-3-rel
mutt-1-11-4-rel
mutt-1-11-rel
mutt-1-12-1-rel
mutt-1-12-2-rel
mutt-1-12-rel
mutt-1-13-1-rel
mutt-1-13-2-rel
mutt-1-13-3-rel
mutt-1-13-4-rel
mutt-1-13-5-rel
mutt-1-13-rel
mutt-1-14-1-rel
mutt-1-14-2-rel
mutt-1-14-3-rel
mutt-1-14-4-rel
mutt-1-14-5-rel
mutt-1-14-6-rel
mutt-1-14-7-rel
mutt-1-14-rel
mutt-1-3-1-rel
mutt-1-3-10-rel
mutt-1-3-11-rel
mutt-1-3-12-rel
mutt-1-3-13-rel
mutt-1-3-14-rel
mutt-1-3-15-rel
mutt-1-3-16-rel
mutt-1-3-17-rel
mutt-1-3-18-rel
mutt-1-3-19-rel
mutt-1-3-2-rel
mutt-1-3-20-rel
mutt-1-3-21-rel
mutt-1-3-22-1-rel
mutt-1-3-22-rel
mutt-1-3-23-1-rel
mutt-1-3-23-2-rel
mutt-1-3-23-rel
mutt-1-3-24-rel
mutt-1-3-25-rel
mutt-1-3-26-rel
mutt-1-3-27-rel
mutt-1-3-3-rel
mutt-1-3-4-rel
mutt-1-3-5-rel
mutt-1-3-6-rel
mutt-1-3-7-rel
mutt-1-3-8-rel
mutt-1-3-9-rel
mutt-1-3-rel
mutt-1-5-1-rel
mutt-1-5-10-rel
mutt-1-5-11-rel
mutt-1-5-12-rel
mutt-1-5-13-rel
mutt-1-5-14-rel
mutt-1-5-15-rel
mutt-1-5-16-rel
mutt-1-5-17-rel
mutt-1-5-18-rel
mutt-1-5-19-rel
mutt-1-5-2-rel
mutt-1-5-20-rel
mutt-1-5-21-rel
mutt-1-5-22-rel
mutt-1-5-23-rel
mutt-1-5-24-rel
mutt-1-5-3-rel
mutt-1-5-4-rel
mutt-1-5-5-1-rel
mutt-1-5-5-rel
mutt-1-5-6-rel
mutt-1-5-7-rel
mutt-1-5-8-rel
mutt-1-5-9-rel
mutt-1-6-1-rel
mutt-1-6-2-rel
mutt-1-6-rel
mutt-1-7-1-rel
mutt-1-7-2-rel
mutt-1-7-rel
mutt-1-8-1-rel
mutt-1-8-2-rel
mutt-1-8-3-rel
mutt-1-8-rel
mutt-1-9-1-rel
mutt-1-9-2-rel
mutt-1-9-3-rel
mutt-1-9-4-rel
mutt-1-9-5-rel
mutt-1-9-rel
mutt-2-0-1-rel
mutt-2-0-2-rel
mutt-2-0-3-rel
mutt-2-0-4-rel
mutt-2-0-5-rel
mutt-2-0-6-rel
mutt-2-0-7-rel
mutt-2-0-rel
mutt-2-1-1-rel
mutt-2-1-2-rel
mutt-2-1-3-rel
mutt-2-1-4-rel
mutt-2-1-5-rel
mutt-2-1-rel
mutt-2-2-1-rel
mutt-2-2-10-rel
mutt-2-2-11-rel
mutt-2-2-2-rel
mutt-2-2-3-rel
mutt-2-2-4-rel
mutt-2-2-5-rel
mutt-2-2-6-rel
mutt-2-2-7-rel
mutt-2-2-8-rel
mutt-2-2-9-rel
mutt-2-2-rel
post-type-punning-patch
pre-type-punning-patch

Git / gitlab.com/muttmua/mutt

Affected ranges

Type
GIT
Repo
https://gitlab.com/muttmua/mutt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

Other

mutt-0-92-10i
mutt-0-92-11i
mutt-0-92-9i
mutt-0-93-unstable
mutt-0-94-10i-rel
mutt-0-94-13-rel
mutt-0-94-14-rel
mutt-0-94-15-rel
mutt-0-94-16i-rel
mutt-0-94-17i-rel
mutt-0-94-18-rel
mutt-0-94-5i-rel
mutt-0-94-6i-rel
mutt-0-94-7i-rel
mutt-0-94-8i-rel
mutt-0-94-9i-p1
mutt-0-94-9i-rel
mutt-0-95-rel
mutt-0-96-1-rel
mutt-0-96-2-slightly-post-release
mutt-0-96-3-rel
mutt-0-96-4-rel
mutt-0-96-5-rel
mutt-0-96-6-rel
mutt-0-96-7-rel
mutt-0-96-8-rel
mutt-0-96-rel
mutt-1-1-1-1-rel
mutt-1-1-1-2-rel
mutt-1-1-1-rel
mutt-1-1-10-rel
mutt-1-1-11-rel
mutt-1-1-12-rel
mutt-1-1-13-rel
mutt-1-1-14-rel
mutt-1-1-2-rel
mutt-1-1-3-rel
mutt-1-1-4-rel
mutt-1-1-5-rel
mutt-1-1-6-rel
mutt-1-1-7-rel
mutt-1-1-8-rel
mutt-1-1-9-rel
mutt-1-1-rel
mutt-1-10-1-rel
mutt-1-10-rel
mutt-1-11-1-rel
mutt-1-11-2-rel
mutt-1-11-3-rel
mutt-1-11-4-rel
mutt-1-11-rel
mutt-1-12-1-rel
mutt-1-12-2-rel
mutt-1-12-rel
mutt-1-13-1-rel
mutt-1-13-2-rel
mutt-1-13-3-rel
mutt-1-13-4-rel
mutt-1-13-5-rel
mutt-1-13-rel
mutt-1-14-1-rel
mutt-1-14-2-rel
mutt-1-14-3-rel
mutt-1-14-4-rel
mutt-1-14-5-rel
mutt-1-14-6-rel
mutt-1-14-7-rel
mutt-1-14-rel
mutt-1-3-1-rel
mutt-1-3-10-rel
mutt-1-3-11-rel
mutt-1-3-12-rel
mutt-1-3-13-rel
mutt-1-3-14-rel
mutt-1-3-15-rel
mutt-1-3-16-rel
mutt-1-3-17-rel
mutt-1-3-18-rel
mutt-1-3-19-rel
mutt-1-3-2-rel
mutt-1-3-20-rel
mutt-1-3-21-rel
mutt-1-3-22-1-rel
mutt-1-3-22-rel
mutt-1-3-23-1-rel
mutt-1-3-23-2-rel
mutt-1-3-23-rel
mutt-1-3-24-rel
mutt-1-3-25-rel
mutt-1-3-26-rel
mutt-1-3-27-rel
mutt-1-3-3-rel
mutt-1-3-4-rel
mutt-1-3-5-rel
mutt-1-3-6-rel
mutt-1-3-7-rel
mutt-1-3-8-rel
mutt-1-3-9-rel
mutt-1-3-rel
mutt-1-5-1-rel
mutt-1-5-10-rel
mutt-1-5-11-rel
mutt-1-5-12-rel
mutt-1-5-13-rel
mutt-1-5-14-rel
mutt-1-5-15-rel
mutt-1-5-16-rel
mutt-1-5-17-rel
mutt-1-5-18-rel
mutt-1-5-19-rel
mutt-1-5-2-rel
mutt-1-5-20-rel
mutt-1-5-21-rel
mutt-1-5-22-rel
mutt-1-5-23-rel
mutt-1-5-24-rel
mutt-1-5-3-rel
mutt-1-5-4-rel
mutt-1-5-5-1-rel
mutt-1-5-5-rel
mutt-1-5-6-rel
mutt-1-5-7-rel
mutt-1-5-8-rel
mutt-1-5-9-rel
mutt-1-6-1-rel
mutt-1-6-2-rel
mutt-1-6-rel
mutt-1-7-1-rel
mutt-1-7-2-rel
mutt-1-7-rel
mutt-1-8-1-rel
mutt-1-8-2-rel
mutt-1-8-3-rel
mutt-1-8-rel
mutt-1-9-1-rel
mutt-1-9-2-rel
mutt-1-9-3-rel
mutt-1-9-4-rel
mutt-1-9-5-rel
mutt-1-9-rel
mutt-2-0-1-rel
mutt-2-0-2-rel
mutt-2-0-3-rel
mutt-2-0-4-rel
mutt-2-0-5-rel
mutt-2-0-6-rel
mutt-2-0-7-rel
mutt-2-0-rel
mutt-2-1-1-rel
mutt-2-1-2-rel
mutt-2-1-3-rel
mutt-2-1-4-rel
mutt-2-1-5-rel
mutt-2-1-rel
mutt-2-2-1-rel
mutt-2-2-10-rel
mutt-2-2-11-rel
mutt-2-2-2-rel
mutt-2-2-3-rel
mutt-2-2-4-rel
mutt-2-2-5-rel
mutt-2-2-6-rel
mutt-2-2-7-rel
mutt-2-2-8-rel
mutt-2-2-9-rel
mutt-2-2-rel
post-type-punning-patch
pre-type-punning-patch

Database specific

vanir_signatures

[
    {
        "target": {
            "file": "sendlib.c"
        },
        "digest": {
            "line_hashes": [
                "311435706394840361027034278408384120933",
                "184811427006018352195317011662055852175",
                "197147681907748699508461669010673632797",
                "115638657409880351838100482405080790463"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "source": "https://gitlab.com/muttmua/mutt@a4752eb0ae0a521eec02e59e51ae5daedf74fda0",
        "deprecated": false,
        "id": "CVE-2023-4874-4ad63683",
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "rfc2047_decode_word",
            "file": "rfc2047.c"
        },
        "digest": {
            "length": 1639.0,
            "function_hash": "53806998968969863017686505986342888599"
        },
        "signature_version": "v1",
        "source": "https://gitlab.com/muttmua/mutt@452ee330e094bfc7c9a68555e5152b1826534555",
        "deprecated": false,
        "id": "CVE-2023-4874-c9f53cf1",
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "write_one_header",
            "file": "sendlib.c"
        },
        "digest": {
            "length": 1537.0,
            "function_hash": "58318663789131637153077802184449394055"
        },
        "signature_version": "v1",
        "source": "https://gitlab.com/muttmua/mutt@a4752eb0ae0a521eec02e59e51ae5daedf74fda0",
        "deprecated": false,
        "id": "CVE-2023-4874-ea8dac3d",
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "rfc2047.c"
        },
        "digest": {
            "line_hashes": [
                "143811940606252416423363556841390520226",
                "267072045718752787410581380108000115876",
                "270087326784847198658990605271372029882",
                "321764223102516675061789209223709827070"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "source": "https://gitlab.com/muttmua/mutt@452ee330e094bfc7c9a68555e5152b1826534555",
        "deprecated": false,
        "id": "CVE-2023-4874-fdb77424",
        "signature_type": "Line"
    }
]