CVE-2007-2683 describes a buffer overflow vulnerability in Mutt 1.4.2, affecting the mutt email client. This flaw allows authenticated local users to execute arbitrary code by injecting ampersand characters into the GECOS field, which then triggers the overflow during alias expansion. The vulnerability carries a CVSS score of 3.5, indicating low severity with a local attack vector, high access complexity, and partial impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-30093) exists, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.2CPE matchmatch criteria | cpe:2.3:a:mutt:mutt:1.4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.