Sceawere
Vulnerability Detail
CVE-2026-107570UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Heap OOB Write in convert_file_from_to
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.5
- Creation Date
- 2h ago
- Vendor
- mutt
- Product
- mutt
- Attack Type
- CWE-823: Use of Out-of-range Pointer Offset
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
heap OOB write in convert_file_from_to() via a crafted Content-Type header allows attacker to OOB write when email is used as a template.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.5",
"pubDate": "2026-10-08T12:17:14.717Z",
"pubdate": "2026-10-08T12:17:14.717Z",
"executiveSummary": "A heap-based out-of-bounds (OOB) write vulnerability exists within the convert_file_from_to() function, triggered by the processing of a maliciously crafted Content-Type header when an email is utilized as a template.\nThis vulnerability allows an attacker to perform unauthorized memory write operations beyond the intended boundaries of the allocated heap buffer.\nThe flaw impacts systems utilizing email templating mechanisms that process user-supplied header metadata.\nSuccessful exploitation may lead to memory corruption, potential code execution, or service instability depending on the memory layout and the nature of the data being written.\nThe attack is primarily driven by the lack of sufficient validation on the Content-Type header during the transformation process.\nExploitation requires the attacker to successfully inject a crafted header into a context where the application processes the email as a template, thereby triggering the flawed memory handling logic.",
"technicalDetails": "The vulnerability resides within the convert_file_from_to() function, which is responsible for mediating file format conversions. The root cause is an improper bounds check on the heap buffer allocated for storing and manipulating data parsed from the Content-Type header of an email template.\nWhen an email is processed as a template, the application parses the Content-Type field. If an attacker provides a crafted, anomalous Content-Type string, the function fails to correctly calculate the required buffer size or enforce strict boundaries during the copy operation. Consequently, the application writes data past the end of the heap-allocated chunk.\nThe exploitation flow begins when the application receives an email containing a maliciously formatted Content-Type header. Upon invocation of convert_file_from_to(), the parser attempts to extract and transform the header data. The logic fails to account for the actual length of the input string relative to the destination buffer, allowing for an out-of-bounds write.\nThis memory corruption can overwrite adjacent objects, control structures, or function pointers located on the heap. By carefully crafting the input, an attacker may influence the integrity of subsequent operations or redirect the control flow to arbitrary code, potentially leading to remote code execution (RCE) with the privileges of the application process.\nThe vulnerability is highly dependent on the heap layout and the specific memory allocator implementation. Because the write is arbitrary or controlled by the input payload, the impact is significant. The absence of adequate input sanitization and length validation within the transformation routine acts as the primary vector for this heap corruption. Because the trigger is part of the standard template processing workflow, an attacker can initiate this without advanced authentication if the email system is exposed to external input, though the exact level of network exposure depends on the architecture of the host system."
}