Total vulnerabilities in the database
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.
Software | From | Fixed in |
---|---|---|
neomutt / neomutt | 20191025 | 20210504.x |
mutt / mutt | 1.11.0 | 2.0.7 |