VYPR

rpm package

opensuse/mutt&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/mutt&distro=openSUSE%20Leap%2016.0

Vulnerabilities (6)

  • CVE-2026-43864LowMay 4, 2026
    affected < 2.2.16-160000.2.1fixed 2.2.16-160000.2.1

    mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.

  • CVE-2026-43863LowMay 4, 2026
    affected < 2.2.16-160000.2.1fixed 2.2.16-160000.2.1

    mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

  • CVE-2026-43862LowMay 4, 2026
    affected < 2.2.16-160000.2.1fixed 2.2.16-160000.2.1

    In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

  • CVE-2026-43861LowMay 4, 2026
    affected < 2.2.16-160000.2.1fixed 2.2.16-160000.2.1

    mutt before 2.3.2 does not check for '\0' in url_pct_decode.

  • CVE-2026-43860LowMay 4, 2026
    affected < 2.2.16-160000.2.1fixed 2.2.16-160000.2.1

    mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

  • CVE-2026-43859LowMay 4, 2026
    affected < 2.2.16-160000.2.1fixed 2.2.16-160000.2.1

    mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.