Mutt mutt_decode_uuencoded() Memory Disclosure
Posted by deepcore on July 12, 2022 – 4:26 pm
In mutt_decode_uuencoded(), the line length is read from the untrusted uuencoded part without validation. This could result in including private memory in replys, for example fragments of other messages, passphrases or keys.
Post a reply
You must be logged in to post a comment.