CVE-2018-14362 log

Source
Severity Medium
Remote Yes
Type Directory traversal
Description
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
Group Package Affected Fixed Severity Status Ticket
AVG-740 neomutt 20180622-2 20180716-1 High Fixed
References
https://github.com/neomutt/neomutt/commit/9bfab35522301794483f8f9ed60820bdec9be59e
https://gitlab.com/muttmua/mutt/commit/6aed28b40a0410ec47d40c8c7296d8d10bae7576