Impact
Heap out‑of‑bounds write vulnerabilities arise in the mutt mail user agent’s convert_file_from_to() routine. By sending a message with a specially crafted Content‑Type header, an attacker can trigger an out‑of‑range pointer offset and overwrite adjacent heap memory. This flaw could corrupt program data, cause crashes, or create a vehicle for arbitrary code execution, depending on the exact memory layout and context. The weakness is classified as CWE‑787.
Affected Systems
The flaw exists in all mutt releases older than 2.4.3. Users running mutt from earlier releases, whether on Linux, macOS, or other platforms, are susceptible unless they have applied the official patch that is included in version 2.4.3 and later.
Risk and Exploitability
The CVSS score of 2.5 places the issue in the low severity range, and the EPSS score is currently unavailable, suggesting no publicly observed exploitation yet. The vulnerability is also not listed in the CISA KEV catalog. Given the requirement of a crafted email header to trigger the OOB write, the theoretical attack vector is an email that the client processes as a template. Although the low CVSS and lack of exploitation evidence reduce immediate risk, the potential for arbitrary memory corruption warrants timely remediation.
OpenCVE Enrichment