← Vulnerability feed

Vulnerability record · CVE-2006-3242 · published 27 June 2006

CVE-2006-3242: Mutt vulnerability

Mutt · Mutt

Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.

7.5 CVSS 2.0 High EPSS 6.0% · top 6.9%
7.5CVSS 2.0 base score
6.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
60References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U
http://dev.mutt.org/cgi-bin/gitweb.cgi?p=mutt/.git%3Ba=commit%3Bh=dc0272b749f0e2b102973b7ac43dbd3908507540
http://dev.mutt.org/cgi-bin/viewcvs.cgi/mutt/imap/browse.c?r1=1.34.2.2&r2=1.34.2.3
http://secunia.com/advisories/20810 Vendor Advisory
http://secunia.com/advisories/20836
http://secunia.com/advisories/20854
http://secunia.com/advisories/20879
http://secunia.com/advisories/20887
http://secunia.com/advisories/20895
http://secunia.com/advisories/20960
http://secunia.com/advisories/21039
http://secunia.com/advisories/21124
http://secunia.com/advisories/21135
http://secunia.com/advisories/21220
http://securitytracker.com/id?1016482
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472221
http://www.debian.org/security/2006/dsa-1108
http://www.gentoo.org/security/en/glsa/glsa-200606-27.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:115
http://www.novell.com/linux/security/advisories/2006_16_sr.html
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.013-mutt.html
http://www.redhat.com/support/errata/RHSA-2006-0577.html
http://www.securityfocus.com/archive/1/438712/100/0/threaded
http://www.securityfocus.com/bid/18642
http://www.trustix.org/errata/2006/0038
http://www.vupen.com/english/advisories/2006/2522
https://exchange.xforce.ibmcloud.com/vulnerabilities/27428
https://issues.rpath.com/browse/RPL-471
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10826
https://usn.ubuntu.com/307-1/
ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U
http://dev.mutt.org/cgi-bin/gitweb.cgi?p=mutt/.git%3Ba=commit%3Bh=dc0272b749f0e2b102973b7ac43dbd3908507540
http://dev.mutt.org/cgi-bin/viewcvs.cgi/mutt/imap/browse.c?r1=1.34.2.2&r2=1.34.2.3
http://secunia.com/advisories/20810 Vendor Advisory
http://secunia.com/advisories/20836
http://secunia.com/advisories/20854
http://secunia.com/advisories/20879
http://secunia.com/advisories/20887
http://secunia.com/advisories/20895
http://secunia.com/advisories/20960

Track CVE-2006-3242 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14349Debian linux improper input validation vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.EPSS 3.2%9.8CVE-2018-14350Mutt out-of-bounds write vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi…EPSS 5.0%9.8CVE-2018-14351Mutt improper input validation vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.EPSS 3.2%9.8CVE-2018-14352Mutt out-of-bounds write vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote character…EPSS 4.0%9.8CVE-2018-14353Mutt vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.EPSS 3.7%9.8CVE-2018-14354Mutt os command injection vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…EPSS 6.2%9.8CVE-2018-14356Debian linux vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.EPSS 3.2%9.8CVE-2018-14357Mutt os command injection vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2006-3242), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.