Debian Bug report logs - #126336
mutt: crash in index

version graph

Package: mutt; Maintainer for mutt is Antonio Radici <antonio@dyne.org>; Source for mutt is src:mutt.

Reported by: Glenn Maynard <glenn@zewt.org>

Date: Mon, 24 Dec 2001 05:03:01 UTC

Severity: normal

Tags: patch

Merged with 133597

Found in versions 1.3.24-2, 1.3.27-2

Fixed in version mutt/1.3.28-2

Done: Marco d'Itri <md@linux.it>

Bug is archived. No further changes may be made.

Forwarded to mutt-dev@mutt.org

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Marco d'Itri <md@linux.it>:
Bug#126336; Package mutt. Full text and rfc822 format available.

Acknowledgement sent to Glenn Maynard <glenn@zewt.org>:
New Bug report received and forwarded. Copy sent to Marco d'Itri <md@linux.it>. Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Glenn Maynard <glenn@zewt.org>
To: submit@bugs.debian.org
Subject: mutt: crash in index
Date: Sun, 23 Dec 2001 23:57:20 -0500 (EST)
Package: mutt
Version: 1.3.24-2
Severity: grave

A mail send to proftpd-users crashes mutt on my system.  I don't know if this
is exploitable, so I erred to caution; if this isn't fixed soon, but isn't
exploitable, change it to Normal.

(Tried to include core information; the script failed and stalled.)

#0  0x0808bab9 in menu_redraw_index ()
#1  0x20202020 in ?? ()

This looks like the culprit:

Subject: [Proftpd-user] =?ks_c_5601-1987?B?W7GksO1dIHByb2Z0cGQtdXNlcnO01CC+yLPnx8+8vL/kLiC0qbG4PyC3zrn2xq7H0riusKEuLrm5PyC8vL26v7W+7lRBUEW4pi4uvvO4tj8gsPjCpbfOLi4g?=

For completeness, uuencoded mail follows:

begin 644 mail
M1G)O;2!P<F]F='`M=7-E<BUA9&UI;D!L:7-T<RYS;W5R8V5F;W)G92YN970@
M(%-U;B!$96,@,C,@,34Z,S$Z,#`@,C`P,0I2971U<FXM4&%T:#H@/'!R;V9T
M<"UU<V5R+6%D;6EN0&QI<W1S+G-O=7)C969O<F=E+FYE=#X*1&5L:79E<F5D
M+51O.B!G7W!F='!D0'IE=W0N;W)G"E)E8V5I=F5D.B!F<F]M('5S=RUS9BUL
M:7-T,2YS;W5R8V5F;W)G92YN970@*'5S=RUS9BUF=S(N<V]U<F-E9F]R9V4N
M;F5T(%LR,38N,3,V+C$W,2XR-3)=*0H)8GD@:#`P-#`S,S-B-V1C,RYN92YM
M961I86]N92YN970@*%!O<W1F:7@I('=I=&@@15--5%`@:60@-#0X,C<Q,$,Y
M,D5!.`H)9F]R(#QG7W!F='!D0'IE=W0N;W)G/CL@4W5N+"`R,R!$96,@,C`P
M,2`Q-3HS,3HP,"`M,#4P,"`H15-4*0I296-E:79E9#H@9G)O;2!L;V-A;&AO
M<W0@*%LQ,C<N,"XP+C%=(&AE;&\]=7-W+7-F+6QI<W0Q+G-O=7)C969O<F=E
M+FYE="D*"6)Y('5S=RUS9BUL:7-T,2YS;W5R8V5F;W)G92YN970@=VET:"!E
M<VUT<"`H17AI;2`S+C,Q+59!+6UM,B`C,2`H1&5B:6%N*2D*"6ED(#$V249$
M,"TP,#`S>'(M,#`[(%-U;BP@,C,@1&5C(#(P,#$@,3(Z,C8Z-3@@+3`X,#`*
M4F5C96EV960Z(&9R;VT@8V]L;&ED92YE=F-O;2YN970@*%LR,38N,3`N,S(N
M-UTI"@EB>2!U<W<M<V8M;&ES=#$N<V]U<F-E9F]R9V4N;F5T('=I=&@@97-M
M='`@*$5X:6T@,RXS,2U602UM;3(@(S$@*$1E8FEA;BDI"@EI9"`Q-DDP0WHM
M,#`P-DQ/+3`P"@EF;W(@/'!R;V9T<"UU<V5R0&QI<W1S+G-O=7)C969O<F=E
M+FYE=#X[(%-A="P@,C(@1&5C(#(P,#$@,C`Z,C4Z-3<@+3`X,#`*4F5C96EV
M960Z(&9R;VT@+2TM+2TM("A;,C$Q+C(Q-RXQ-#,N,S5=*0H)8GD@8V]L;&ED
M92YE=F-O;2YN970@*#@N,3$N,R\X+C$Q+C,I('=I=&@@4TU44"!I9"!F0DXT
M4&]',#DP-3D*"69O<B`\<')O9G1P9"UU<V5R<T!P<F]F='!D+F]R9SX[(%-A
M="P@,C(@1&5C(#(P,#$@,C,Z,C4Z-3$@+3`U,#`*365S<V%G92U)9#H@/#(P
M,#$Q,C(S,#0R-2YF0DXT4&]',#DP-3E`8V]L;&ED92YE=F-O;2YN970^"D9R
M;VTZ(#T_:W-?8U\U-C`Q+3$Y.#<_0C]W37EZ-CA3+W5C2S!Z.%1*=TUY.'AW
M/3T_/2`\=V5B;6%S=&5R0&UA:6QP87)T;F5R+F-O+FMR/@I4;SH@<')O9G1P
M9"UU<V5R<T!P<F]F='!D+F]R9PI-24U%+59E<G-I;VXZ(#$N,`I#;VYT96YT
M+51Y<&4Z(&UU;'1I<&%R="]A;'1E<FYA=&EV93L*"6)O=6YD87)Y/2(M+2TM
M/5].97AT4&%R=%\P,#!?,#$S-U\P,4,P1C(S02XY,T$Q,4,P,"(*6"U0<FEO
M<FET>3H@,PI3=6)J96-T.B!;4')O9G1P9"UU<V5R72`]/VMS7V-?-38P,2TQ
M.3@W/T(_5S=':W-/,61)2$)Y8C):,&-'471D6$YL8VY/,#%#0RMY3%!N>#@K
M.'9,+VM,:4,P<6)'-%!Y0S-Z<FXR>'$W2#!R:75S2T5U3')M-5!Y0SAV3#(V
M=C=7*S=L4D)515<T<&DT=79V3S1T:CAG<U!J0W!B9D],:31G/ST*4V5N9&5R
M.B!P<F]F='`M=7-E<BUA9&UI;D!L:7-T<RYS;W5R8V5F;W)G92YN970*17)R
M;W)S+51O.B!P<F]F='`M=7-E<BUA9&UI;D!L:7-T<RYS;W5R8V5F;W)G92YN
M970*6"U"965N5&AE<F4Z('!R;V9T<"UU<V5R0&QI<W1S+G-O=7)C969O<F=E
M+FYE=`I8+4UA:6QM86XM5F5R<VEO;CH@,BXP+C4*4')E8V5D96YC93H@8G5L
M:PI,:7-T+4AE;'`Z(#QM86EL=&\Z<')O9G1P+75S97(M<F5Q=65S=$!L:7-T
M<RYS;W5R8V5F;W)G92YN970_<W5B:F5C=#UH96QP/@I,:7-T+5!O<W0Z(#QM
M86EL=&\Z<')O9G1P+75S97)`;&ES=',N<V]U<F-E9F]R9V4N;F5T/@I,:7-T
M+5-U8G-C<FEB93H@/&AT='!S.B\O;&ES=',N<V]U<F-E9F]R9V4N;F5T+VQI
M<W1S+VQI<W1I;F9O+W!R;V9T<"UU<V5R/BP*"3QM86EL=&\Z<')O9G1P+75S
M97(M<F5Q=65S=$!L:7-T<RYS;W5R8V5F;W)G92YN970_<W5B:F5C=#US=6)S
M8W)I8F4^"DQI<W0M260Z(%!R;T944$0@=7-E<G,@<W5P<&]R="!L:7-T(#QP
M<F]F='`M=7-E<BYL:7-T<RYS;W5R8V5F;W)G92YN970^"DQI<W0M56YS=6)S
M8W)I8F4Z(#QH='1P<SHO+VQI<W1S+G-O=7)C969O<F=E+FYE="]L:7-T<R]L
M:7-T:6YF;R]P<F]F='`M=7-E<CXL"@D\;6%I;'1O.G!R;V9T<"UU<V5R+7)E
M<75E<W1`;&ES=',N<V]U<F-E9F]R9V4N;F5T/W-U8FIE8W0]=6YS=6)S8W)I
M8F4^"DQI<W0M07)C:&EV93H@/&AT='`Z+R]W=W<N9V5O8W)A=VQE<BYC;VTO
M<F5D:7(M<V8N<&AP,S]L:7-T/7!R;V9T<"UU<V5R/@I8+4]R:6=I;F%L+41A
M=&4Z(%-U;BP@,C,@1&5C(#(P,#$@,3,Z,3$Z-#D@*S`Y,#`*1&%T93H@4W5N
M+"`R,R!$96,@,C`P,2`Q,SHQ,3HT.2`K,#DP,`H*5&AI<R!I<R!A(&UU;'1I
M+7!A<G0@;65S<V%G92!I;B!-24U%(&9O<FUA="X*"BTM+2TM+3U?3F5X=%!A
M<G1?,#`P7S`Q,S=?,#%#,$8R,T$N.3-!,3%#,#`*0V]N=&5N="U4>7!E.B!T
M97AT+W!L86EN.PH)8VAA<G-E=#TB:W-?8U\U-C`Q+3$Y.#<B"D-O;G1E;G0M
M5')A;G-F97(M16YC;V1I;F<Z(&)A<V4V-`H*=2]N2'<W1WIW3V-O>&1F07I-
M9D)+8FEM=60V*WAR<31S3S(Y>F-#-'9C5S8P34,V=V1A.#!R:6US94Q!-3AF
M4'9C6$EX0S8K"GAR96AW364Y>&-/-W@X*W@T<FXR>')$074X5W-U2R](>C=Y
M.'8K475)03!+24$P2T11;TY#9S!+1%%O3D-G,$M$46].0V<P2PI)03!+1%%Q
M-RMC9D1X9&9!>DUF0DE,,T9W-W9!,G)40TE-2%=V3DQ)<G-$3W-0;V=X.5-Y
M<VE#-7$W9FAT.#1G<V)0035Y06<*=61C9W@X1S-Z<DA8=#953D-R=GIT3U!!
M=7E#=SA,;EIT.#1G=60W075,,TA)3'HR24U$5W9C0S!Z-U1:3&E!3D-G,$M$
M46]."D-G,$M)03!+1%%O3D-G,$M$46].0VE!3D-G,$M$46]G24-!3D-I06=)
M1#0K4&E!9W8O:D5O4T,K>7)40TE,:F5W32]!=7E#-0HS<T,T=DUY,#)B:G!)
M341-=V%%9W9U9D@R369924U(5W9C3W@T:4,U,F)B-'1-*S`R4S1G24$P2TE#
M06=)0T%G24-#.#ER,T8*=TQS9TE,+S1X2T5G=G-R075,,T1U3VMG=G-A,V]3
M1$%Z3&IE=TTX9W=D83@P<FEM24U$570X3$AZ-S-$<T\P9W9083EX8D1&"G5S
M-&=)3&XR>')$075Y1$9R3&EV>#EG9W=D83EW-TAI24QN6G1V:3!Z-U1:3&E!
M3D-I06=)0T%G24-!9W5A-T%X>4%G3VE$00IZ3%!R>$PK-7=R5%!X36Y!>DQZ
M2$E#9W=-:6LR37I5>$Q48S%-1$%G24-!9TE#06=)2&1L66TQ:&,S4FQC:T)T
M65=L<V-'1GD*9$<U;&-I-6IB>35R8V<P2TE#04I#46M*0U-!9TE#04Y#:4%G
M24-!9TE#06=)341-=4XW07IY06=W3E,S=VE!9TE!:TI#46M*"D-1:TI#4T%G
M24$P2TE#06=)0T%G24$P2PH*+2TM+2TM/5].97AT4&%R=%\P,#!?,#$S-U\P
M,4,P1C(S02XY,T$Q,4,P,`I#;VYT96YT+51Y<&4Z('1E>'0O:'1M;#L*"6-H
M87)S970](FMS7V-?-38P,2TQ.3@W(@I#;VYT96YT+51R86YS9F5R+45N8V]D
M:6YG.B!B87-E-C0*"E!':#!B5W<K0V=O.&%'5FA:1#1+4$A2<&1'>&Q0<G8U
M>#A/>',X1&Y+35A8=TUZ2'=3;31P<FYE=G-A-G5,1'1V8S-!=4PS1@IU=$1!
M=7-(5W9.2S1P<DAI=T]F2'HW,T9Y35%U=G-A,V]C1$AV8UA$=3AF4'-E2S4Y
M<V%W=TQV1G),:79X."LX=DPO:TQJ=W8*9$=L,&)'52M#:GAZ63-*<&-(46=B
M1T9U6C-6:%HR53E);7!H9&U&>EDS2G!C2%%I4&=O.$E3,'1#;5HQ8FU.,&%7
M.75)2$YL"F)M4FUB,TIT2T-K2V5W;V=)0T)P6FEH:V(R3C%B5U9U9$,U;6(S
M2G1-4S5U65<Q;$QN6FAB2%9L4%0P:4EI;#=#:4%G24-!9PI)1T9S6EA*,$M#
M3$%Z3&EN=TQS9W=.4S-W<V90=C9K9W=D83EY<C-$=BM1=4QN0G-:5T9Z6E,T
M:4M4<TM)0T%G24-!9V-M5C`*9%A*=4E'6FAB2$YL3W=O9TE#0CE#:4%G24=L
M;4M'4G99,U9T6E<U,$QM6G9C;3!X3&Y2;&)$175D;49S9%=5.5!326E+6'-+
M"DE#06=)0T%G65=X;&-N46])<T0X>4LR-2M-:6IU2UEG=TY3,W=S9E!V-FMG
M=V1A.7ER,T1V*U%U3&Y"<UI71GI:4S1I2U1S2PI)0T%G24-!9V-M5C!D6$IU
M24=::&)(3FQ/=V]G24-".4-I06=)1VQM2T=2=EDS5G1:5S4P3&U:=F-M,'A,
M;E)L8D1)=61M1G,*9%=5.5!326E+6'-+24-!9TE#06=95WAL8VY1;TES9F%T
M95A'*V)N-'E+3S1P:41!,4QF0W@X*R]Q4T1",7(S2W9C3R\U0S1U"F-'>&Q9
M6$YL3&E)<$]W;V=)0T%G24-">5I84C%C;31G6FU&<V,R53=#:4%G24@P2TE#
M06=A5UEO6D<Y:F17,6QB;E%U6FTY>0IB5$5U6E<Q:&%7=W5D;49S9%=5.5!3
M26E+6'-+24-!9TE#06=95WAL8VY1;TES1$UU3C=!>CA#-TE-1%5T.$Q(>C<K
M<$E-2%<*=F-Q.7<W+VM,:35W8D=6:&,R575):6LW0VE!9TE#06=)2$IL9$A6
M>6)I0FU95WAZ6E1S2TE#06=F46]G24-"<%II:&MB,DXQ"F)75G5D0S5M8C-*
M=$U3-6A:1U)Y6EA.>DQN6FAB2%9L4%0P:4EI;#=#:4%G24-!9TE'1G-:6$HP
M2T-,0C%R>E-U2UEG=TY3,PIW<V90=C9K9W=D83EY<C-$=BM1=4QN0G-:5T9Z
M6E,T:4M4<TM)0T%G24-!9V-M5C!D6$IU24=::&)(3FQ/=V]G24-".4-G:V<*
M24-!9TE#0FMB,DXQ8E=6=61#-6UB,TIT35,U>F172G1A6%%O2U1S2V91<&UD
M5S5J9$=L=F)I0GI:5S5K85A1;TM1<#=#:4%G"DE';&U+1U)V63-6=%I7-3!,
M;5IV8VTP>4QM5G195VQS3&Y::&)(5FQ05#!I26EL-T-I06=)0T%G24=&<UI8
M2C!+0TQ!>DQJ90IW32]!=7E$03%,9D-X."LO<5-$0C%R,TMV8T\O-4,T=6-'
M>&Q96$YL3&E)<$]W;V=)0T%G24-">5I84C%C;31G6FU&<V,R53<*0VE!9TE(
M,$M#4T%G24-!9TE'4G99,U9T6E<U,$QM6G9C;3!Y3&Y.,5EM,7!D0V=P3W=P
M.4-I.'9,4S`K0VIW=E4P3E-35D)5"E!G;SA,,FAL65=1*T-G;SA9;3EK95-"
M:5HR3G9B1SEY4%-*,V%';#!:4TEG9$=6-&1$,&E9;7AH63)S:4E'>'!B;7,Y
M26U*<PID5U5I24A:<V%7-7)04TIW9%A*=V)'56E)1T9S85<U<E!32GE:5U%I
M4&=O.%1%1EI25DEG84=6<%HR:#!04TEY36E)9T-N9'`*6DA2;U!327A):4%+
M8S-*:E!32F]D2%)W3VDX=EE747A,;49T65=L<TQM3G9,;71Y3#)&:TPR.7=:
M5S5K3&UH,&)7=R]C1CEP"EI$,4)-:D%W351%>$U$67=-1$%W37E::&)803=B
M5CEP6D0P=T]$27E-1$%W3FI%>D]#6FAB6$$W8E=T9F%743E-1$5I24=L:PI0
M4TIS65AL;&-J16E)1WAL6FY1.4EJ57=):4(P8C-!.4EJ57=):4(V3%=L=5I'
M5C104TEX26HT2TE#06=)1'AW4&E:=5EN3G<*3WIW=F-$-$M00SE-459L1E5J
M-$M015)*5FE">F1(;'-:5#!I4FLY3U9$;V=-5$)W9$-#>'9,:7E):C1+4$52
M2E9I0FAB1VQN"F)J,6I:5S4P6EA)*T-J>%5154I-4E-":EI7>'-5,T)H63)L
M=5IZ,'=)1TYL8D=X45E74FMA5S5N4%1!9V0R;&MD1V<Y3FI-,@I)1T9S85=D
M=5!73FQB;E)L8VE!2UEM1FIA,F1Y8C-6=5I$,6]D2%)W3VDX=EE747A,;49T
M65=L<TQM3G9,;71Y3#)&:TQZ27<*341%=DU41799,E9Z351%=TYI.7!B5V-V
M66UC=5HR;&U)1TIV8VU2;&-J,'=09V\X5D5*4%)&:RM#:GA556HT2U!&4D50
M:GAP"F)78V=C,TIJ4%-*;V1(4G=/:3AV9#-D,TQM,6AA5WAW65A*,&)M5GE,
M;4YV3&UT>4PR5G195VQS3#)6=%E7;'--4S5N85=9:0I)2&1P6DA2;U!323)-
M>EEI24=H;&%79&]D1#!I351)>$EI0FEB,TIK6EA).4EJ06E0:G=V5D51*U!#
M.555:C1+4$924TE(6D(*8D=L;F)J,3!B,T$K0VIX55)#0F]:5VQN84A1.4]$
M8S!09V\X4D5L5TE'1G-A5V1U4%=.;&)N4FQC:C0X4U4Q2$E!<&]:5VQN"F%(
M43E.>F-G8S-*:E!32F]D2%)W3VDX=EE747A,;49T65=L<TQM3G9,;71Y3#)&
M:TQZ27=-1$5V351%=EDR5GI-5$5W3FDY<`IB5V-V9$=6-&1$07=-4S5N85=9
M:4E!<#-A5U(P840P,$Y$56=9;3EY6D=6>5!402M014I34&=O.%9%1D-4155G
M63)6<V)&3G<*65=.<&)M8SE-0T)J6E=X<U5'1FM:1VQU6GHP=TE(9'!:2%)O
M4%-)-4Y356E)1T9S85=D=5!73FQB;E)L8VE":6(S2FM:6$DY"DU$-$M01E)#
M5#!26E!G;SA61DDK0VIX55)#0C-A5U(P840P:4Y$56Q):C1+4$522E9I0FAB
M1VQN8FHQ>6%79&]D1#0X4U4Q2`I)1VAL85=D;V1$,#-/4T%+8S-*:E!32F]D
M2%)W3VDX=EE747A,;49T65=L<TQM3G9,;71Y3#)&:TQZ27=-1$5V351%=EDR
M5GH*351%=TYI.7!B5V-V8S)&<6%7-'=-1$5U6C)L;4EI04MD,FQK9$=G.4U4
M9WI0:G=V4D5L5U!J=W9615$K0VIX55)#0C-A5U(P"F%$,&E.5%5L26HT.%-5
M,4A)1VAL85=D;V1$,#-/4T%+8S-*:E!32F]D2%)W3VDX=EE747A,;49T65=L
M<TQM3G9,;71Y3#)&:PI,>DEW341%=DU41799,E9Z351%=TYI.7!B5V-V8S)&
M<6%7-'=-1$EU6C)L;4EI04MD,FQK9$=G.4UJ9WA0:G=V5D51*U!#.54*56HT
M2U!&4E-09V\X5D519V0R;&MD1V<Y26I1,4I322M#:GA%4U999UE7>'!:,C0Y
M8VUL;F%(42M016Q.4GE";UI7;&YA2%$Y"DUJ231)07!Z8VU-.4EM:#!D2$$V
M3'DY:%I$17595S%H85=W=5DR.'5A,TEV65=1=DUJ07=-4SAX35,Y:EI837A-
M5$$R3#)L=`I:>3EZ65=P<&)J07=->35Q8T=C:4E!<#-A5U(P840P>$]$32M0
M0SE%4U99*U!#.5521#1+4$9214E(6D)B1VQN8FHQ,&(S06<*9#)L:V1'9SE)
M:E4Q2E-)*U!%;$Y2>4%+84=6<%HR:#!05$EY3T-">F-M33E);6@P9$A!-DQY
M.3-D,V-U8E=&<&)(0FAC;E)U"EI82759,CAU83-)=EI7,6AA5W=V6E<Q:&%7
M=WI,;61P6FE)9T-N9'!:2%)O4%11>$YI0FEB,TIK6EA).4U$-#A,,5)%4&IW
M=@I61DDK4$,Y55%K.4575#0X3#%20E%K>$90:GA#56HT2U!&4D)1:WA&24=.
M;&)'>%1C1T9J85<U;E!406=9,E9S8D9":%I'4G`*8FUC.4U#0C-A5U(P840P
M:4]426Q):4)H8D=L;F)J,6I:5S4P6EA)9T-M2FA9,G1N8VTY,6)M43EA2%(P
M8T1O=DPR1FM-4S5H"F)71G!B0S5J8GDU<F-I.6A:0SAY341!>$QZ17A,,DYL
M8WI%>$U$679A5S%N3#-.;&-407=-:35N85=99UEM.7E:1U9Y4%1!*PI#:GA5
M46LY15=4-$M01E)34&=O.%9%46=A1U9P6C)H,%!417A0:GA*5%5C9V%'5G!:
M,F@P4%1)>$E!<'IC;4TY26UH,&1(038*3'DY:%I$17595S%H85=W=5DR.'5A
M,TEV65=1=DUJ07=-4SAX35,Y:EI837A-5$$R3#)L=%IY.7I:6$5W341%=5HR
M;&U):4%+"F0R;&MD1V<Y3E1G>E!J=W9615$K4$,Y555J-$M01E)324A:0F)'
M;&YB:C$P8C-!*T-J>%520T)O6E=L;F%(43E-5&-Y4&=O.`I6149#5$559UDR
M5G-B1DYW65=.<&)M8SE-0T)J6E=X<U5'1FM:1VQU6GHP=TE(9'!:2%)O4%-)
M-4Y356E)1T9S85=D=5!73FP*8FY2;&-I0FEB,TIK6EA).4U$-$M01E)#5#!2
M6E!G;SA61DDK0VIX55)#0C)15WAP6C(T.61'.7=)2&1P6DA2;U!323!.>55I
M"DE':&QA5V1O9$0P>4U$-$M015)*5FE":&)';&YB:C%Y85=D;V1$-#A353%(
M24=H;&%79&]D1#!Z36E!2V,S2FI04TIO9$A2=PI/:3AV65=1>$QM1G195VQS
M3&U.=DQM='E,,D9K3'I)=TU$179-5$5V63)6>DU417=.:3EP8E=C=F,R;'1-
M1$%X3&UD<%II26<*0VYD<%I(4F]05$DQ350T.$PP4DI6:C0X3#%215!G;SA6
M15%G84=6<%HR:#!05$TQ24A*=F0Q3G=95S0Y36HT.%-5,4A)1VAL"F%79&]D
M1#!X3U1-9T-N3GE9>C!I84A2,&-$;W9,,D9K35,U:&)71G!B0S5J8GDU<F-I
M.6A:0SAY341!>$QZ17A,,DYL8WI%>`I-1%EV85<Q;DPS3FAA;6QU341!,4QM
M<'=:>4EG0VYD<%I(4F]05$DU3FHT.$PQ4D50:G=V5D9)*T-J>%55:C1+4$92
M14E(6D(*8D=L;F)J,3!B,T%G9#)L:V1'9SE):E$S2E-)9V%'5G!:,F@P4%15
M,%!G;SA216Q724=&<V%79'506$IP6C)H,%!J>$-5:C0X"E-5,4A)1VAL85=D
M;V1$,'A-1%%G0VY.>5EZ,&EA2%(P8T1O=DPR1FM-4S5H8E=&<&)#-6IB>35R
M8VDY:%I#.'E-1$%X3'I%>`I,,DYL8WI%>$U$679A5S%N3#-.<&)407=-:35N
M85=9:4E!<#-A5U(P840P>4Y432M00SE%4U99*U!#.5521#0X3#%24U!J=W8*
M5D5*4%)&:RM00SE5455*35)4-#A,,5)%4&IW=E9&22M#:GA556HT2U!&4D50
M:GA*5%5C9V%'5G!:,F@P4%1)=TE!<'IC;4TY"DEM:#!D2$$V3'DY:%I$1759
M5S%H85=W=5DR.'5A,TEV65=1=DUJ07=-4SAX35,Y:EI837A-5$$R3#)L=%IY
M.7I:6$5W341-=0I:,FQM26E!2V0R;&MD1V<Y3E1G>E!J=W9615$K4$,Y555J
M-#A,,5)#5#!26E!J=W96149#5$55*U!%2E-09V\X5D5&0U1%56<*63)6<V)&
M3G=95TYP8FUC.4U#0FI:5WAS54=&:UI';'5:>C!W24AD<%I(4F]04TDU3E-5
M:4E'1G-A5V1U4%=.;&)N4FQC:4)I"F(S2FM:6$DY340T2U!&4D-4,%):4&=O
M.%9&22M#:GA54D-",V%74C!A1#!I351K;$EI0F]:5VQN84A1.4UJ53109V\X
M4D5L5PI)1T9S85=D=5!82G!:,F@P4&IX2E158V=A1U9P6C)H,%!423%.4T%+
M8S-*:E!32F]D2%)W3VDX=EE747A,;49T65=L<TQM3G8*3&UT>4PR1FM,>DEW
M341%=DU41799,E9Z351%=TYI.7!B5V-V6C-*;%I7-'=-1$5U6C)L;4EI04MD
M,FQK9$=G.4UZ:RM00SE%"E-662M00SE54D0T2U!&4D5)2%I"8D=L;F)J,3!B
M,T%G9#)L:V1'9SE):EEZ2E-)9V%'5G!:,F@P4%1),4]$-$M015)*5FE":`IB
M1VQN8FHQ:EI7-3!:6$DK4$5L3E)Y0F]:5VQN84A1.4UJ8V=#;DYY67HP:6%(
M4C!C1&]V3#-D,V1Y-7195VQS8T=&>61'-6P*8VDU:F)Y-7)C:3EL8E=&<&)#
M.6QB5T9P8D1)=5HR;&U):4(S85=2,&%$,'E/5$TK241X2E158V=#;6AL85=D
M;V1$,#%.:4)Z"F-M33E);6@P9$A!-DQY.6A:1$5U65<Q:&%7=W59,CAU83-)
M=EE7479-:D%W35,X>$U3.6I:6$UX351!,DPR;'1:>3DP6EAH,`I-1$%Z3&UD
M<%II26=#;F1P6DA2;U!433).>C1G4$5*4U!J>$-5:C0X4FLY3U9#0GIA6'!L
M4%1)*W4O;DAW.%A8=TUZ2'=30SD*>&-/-W=.<3!W:41",7)Z4WE+-T%Z<D0V
M24UF57-R26=U874S-&)F3TE,1WIW3V-G0VE!9TE#06=)0T%G24-!9TE#06=)
M0T%G"DE#06=)0T%G24-!9TE#06=)0T%G24-!9TE#06=)0T,U,7E$2'=B9D]S
M9&4S<%1X:6-J-C<X-U1J=TQS9W-00S4R8F9/24QN90IW3&DY>'E#.#EI1$$Q
M<C-!=$TK,#)3-&=014I34&IX0U5J-#A,,%I05&Q1*U!#.4535EDK0VIX1U0Q
M2DY)1S5H8E=5.4EM6G8*8VTP>$EI0FA9,U)P8C(T.4EM:#!D2$$V3'DY,V0S
M8W5B5T9P8DA":&-N4G5:6$EU63(X=6$S279:5S%H85=W=EI7,6AA5WAF"F(R
M<W596$YW26E"=%I84F]B,E$Y26Y"=F,S46E09V\X5D5&0U1%56=9,E9S8D9.
M=UE73G!B;6,Y34-":EI7>'-51T9K6D=L=0I:>C!W24AD<%I(4F]04TDU34-5
M:4E'1G-A5V1U4%=.;&)N4FQC:4)I8C-*:UI823E-1#1+4$920U0P4EI09V\X
M5D9)*T-J>%4*4D-",E%7>'!:,C0Y9$<Y=TE(9'!:2%)O4%-),DUI56E)1VAL
M85=D;V1$,'A.1$$K0VIX15-666=95WAP6C(T.5DR5G5D1U9Y"E!G;SA6149#
M5$559UDR5G-B1DYW65=.<&)M8SE-0T)J6E=X<U5'1FM:1VQU6GHP=TE(9'!:
M2%)O4%-)-4U#56E)1TIV8VU2;`IC:C!W4&=O.%9%2E!21FLK0VIX555J-$M0
M1E)%24A:0F)';&YB:C$P8C-!9V0R;&MD1V<Y26I-,DI326=A1U9P6C)H,%!4
M17H*3FHT2U!&02M016Q.4GE">F-M33E);6@P9$A!-DQY.3-D,V-U8E=&<&)(
M0FAC;E)U6EA)=5DR.'5A,TEV6E<Q:&%7=W9:5S%H"F%7=S!,;61P6FE)9T-N
M9'!:2%)O4%15,E!J=W951#0X3#%215!G;SA615%G9&M&<V%79'506%)V8T-"
M,V%74C!A1#!I3FI1;`I):4)O6E=L;F%(43E-5$TR4&IX1U0P-55)2$YP96U5
M.4UJ-#A353515E919V)71C141U9U6C-2;U!413%)2$YP96U5.4U406<*0VTU
M:&)753E);35H8E=5:5!I03A1;$DK4$5L3U5&5E5)1S%H945X;&)M9#!A1#!X
M3E-">F%8<&Q05$5W24<U:&)753E);E)L"F)$16E0:4$X46Q)*U!%;$]51E95
M24<Q:&5%>&QB;60P840P>$Y304MC,FPV6E0P>$U#0G595S%L4%-*,%I7=WE)
M:C1G4$5*4PI0:GA*5&Q"5E9#0G196&A-6E<U;F1'9SE->D%G8S)L-EI4,'A.
M:4)U65<Q;%!32FQB5T9P8D-)*U!%2E-0:GA*5&Q"5E9#04L*8S)L-EI4,'A.
M:4)U65<Q;%!32FA:1U)Y6EA.>DEJ-&=00SE'5#`U55!J=W9615$K4$,Y555J
M-#A,,5)#5#!26E!J=W96149#"E1%52M00SE%4U99*U!#.5521#1+4$9214E(
M9'!:2%)O4%-)>D]#56E)1VAL85=D;V1$,'A.1$$K0VIX15-666=95WAP6C(T
M.0I9,E9U9$=6>5!J>$I4;$)65D-",&580FQ05VQT65=D;$E':&QA5V1O9$0P
M>$U$06=D,FQK9$=G.4U407=)07!Z8VU-.4EM:#`*9$A!-DQY.6A:1$5U65<Q
M:&%7=W59,CAU83-)=EE7479-:D%W35,X>$U3.6I:6$UX351!,DPR;'1:>3EI
M9%A2,&(R-'5:,FQM"DEI0FAB1VQN8FHQ,&(S06=#;4IV8VU2;&-J,'=)1SEU
M63)X<%DR<SE);DYL8FU2;6(S2G1+0VMI4&IW=E)%;%=0:G=V5D51*PI00SE5
M56HT.$PQ4D-4,%):4&IW=E9%1D-4154K0VE!9TE#06=)0T%G24-!9TE#06=)
M0T%G24-!9TE#06=)0T%G24-!9TE#06<*24-!9TE$=W9:;3EY8E0T2U!%6E!4
M;%%G8S)L-EI4,'E0:G=V4FLY3U9$-#A,,5)%4&=O.%9%46=D,FQK9$=G.4EJ
M131*4TEG"F%'5G!:,F@P4%1),4]$-#A353%(24=H;&%79&]D1#!Y3E159T-N
M3GE9>C!I84A2,&-$;W9,,D9K35,U:&)71G!B0S5J8GDU<@IC:3EH6D,X>4U$
M07A,>D5X3#).;&-Z17A-1%EV85<Q;DPR9'E:5U9U341!>4QM9'!::4EG0VYD
M<%I(4F]05$TT4&IW=E9%42L*4$,Y555J-#A,,5)#5#!26E!J=W96149#5$55
M*U!#.4535EDK4$,Y55)$-#A,,5)34&=O.%9&22M#:GA54D0T.%-5,4A)1VAL
M"F%79&]D1#!Y3T-">F-M33E);6@P9$A!-DQY.6A:1$5U65<Q:&%7=W59,CAU
M83-)=EE7479-:D%W35,X>$U3.6I:6$UX351!,@I,,FQT6GDY:5IZ07E,;61P
M6FE)9T-N9'!:2%)O4%19>DYJ-#A,,5)%4&IW=E9&22M00SE546LY15=4-#A,
M,5)"46MX1E!J>%4*455*35)30FI:5WAS53-":%DR;'5:>C!W24=.;&)'>%%9
M5U)K85<U;E!406=D,FQK9$=G.4Y4531)1T9S85=D=5!73FQB;E)L"F-I0FEB
M,TIK6EA).4U$-$M01E)#5#!26E!G;SA61DDK0VIX55)$-$M00SE54D0T.$PQ
M4E-0:G=V5D5*4%)&:RM00SE5455*30I25#0X3#!22E9J-#A,,%)*5FHT2U!(
M06=95WAP6C(T.4EM3FQB;E)L8VE)*U!%;$Y2>4%+84=6<%HR:#!05$5G0VY.
M>5EZ,&D*84A2,&-$;W9,,D9K36DU:&)71G!B0S5J8GDU<F-J;S1-1&=W3#)6
M=&-Y.7E:5TYL85A:;&-J.7=8,FQK4%5%>4U$07A-5$5W"DYJ07=-1$%Z2FU&
M=&-$='18,FQK4%1!-$UJ27=-1$$R351--$IM1G1C1'0P6#-2-6-'53E.5%%M
M65<Q=T\S4F99,CEK6E0P>0I-0TEG0VYD<%I(4F]05$4K0VIX,%E72G-:4T)H
M8D=L;F)J,&E9,E9U9$=6>4EI0FEB,TIK6EA).4EJ06E)1TYL8D=X=UE74FL*
M85<U;E!327=):4)J6E=X<V,S0FA9,FQU6GHP:4U#26=D,FQK9$=G.4EJ67I.
M:4EG84=6<%HR:#!04TEX3E1!:5!G;V=)0T%G"E!(4GE09V]G24-!9TE#06=)
M1'@P6D-">F1(;'-:5#!I66U&:F$R9'EB,U9U6D,Q<&)71FY:5'`Q8VUW;THR
M:#!D2$$V3'DY,PID,V-U8E=&<&)(0FAC;E)U6EA)=5DR.'5A,TEV6E<Q:&%7
M=W9:5S%H85=W,4QM9'!::6-P3WE":5E73G):,TIV9%<U:TQ82FP*8T=6:&1$
M<'5B>3%Y6EA";%E843=):C1+24-!9TE#06=)0T%G24-!9U!'2GE0:G@P65=*
M<UI30FEB,TIK6EA).4EJ06E)2&1P"EI(4F]04TEX341!;$EJ-$M)0T%G24-!
M9TE#06=)0T%G24-!9TE$>#!C:C1+24-!9TE#06=)0T%G24-!9TE#06=)0T%G
M24-!.`ID1U%G9#)L:V1'9SE):EEY3FE)*T-I06=)0T%G24-!9TE#06=)0T%G
M24-!9TE#06=)0T%G241X=TE(3C!E5WAL4%-*<V%7-6P*3%=H;&%79&]D1&]X
M3E1!;$]Y0G196$IN85<T=&1'.7=/:D$W24<Q:&-M9'!B:3%I8C-2,&(R,#9-
M1'-G8E=&>5HR;'5,5WAL"EIN439-:D$W26HT.&,S0FAB:4)Z9$AL<UI4,&E:
M;3EU9$,Q>F%8<&Q/:FQW9$1S:5!J>&UB,C4P24=::%DR53E)<D<X=4Q):0I0
M:5IN9$1S;5HS43=*;60P3WE!2TE#06=)0T%G24-!9TE#06=)0T%G24-!9TE#
M06=)0T%G=B]J16]30RMY<E1#24QJ97=-+T$*=7E#-3-S0S1V37DP,F)J<$E-
M1$UW845G=G5F2#)-9EE)34A7=F-/>#1I0S4R8F(T=$TK,#)3-&=#:4%G24-!
M9TE#06=)0T%G"DE#06=)0T%G24-!9TE#06=)1'=V6FTY=61$-#A,,TYW65<T
M*U!#.7=09V]G24-!9TE#06=)0T%G24-!9TE#06=)0T%G24-!9PI)0T$X8T-"
M>F1(;'-:5#!I8D=L=5I3,6]:5VQN84A1-DU457=*5'-G8E=&>5HR;'5,6%)V
M8T1O=T]Y0G196$IN85<T=%EM.3`*9$<Y=$]J03=)1S%H8VUD<&)I,7-:5UHP
M3VI)=T]Y22M02$YW65<T9V,S4C5B1U4Y26U:=F)N471C,FPV6E1O-6-(43=)
M:C0X"EIM.75D0T)M65=.;%!32WAV3&EY26HT;6)M2GIC1'-M8FU*>F-$<VUB
M;4IZ8T1S;6)M2GIC1'-M8FU*>F-$<VUB;4IZ8T1S;0IB;4IZ8T1U.#ER,T9W
M3'-G0VE!9TE#06=)0T%G24-!9TE#06=)0T%G24-!9TE#06=)3"\T>$M%9W9S
M<D%U3#-$=4]K9W9S83,*;U-$07I,:F5W33AG=V1A.#!R:6U)3415=#A,2'HW
M,T1S3S!G=E!A.7AB1$9U<S1G0VE!9TE#06=)0T%G24-!9TE#06=)0T%G"DE#
M06=)0T%G24QN,GAR1$%U>41&<DQI=G@Y9V=W9&$Y=S=(:4E,;EIT=FDP>C=4
M6DQI03A,,EIV8FY1*U!#.7IC1T9U4&IW=@IC1#1+24-!9TE#06=)0T%G24-!
M9TE#06=)0T%G24-!9TE#06=02$%G8S-2-6)'53E);7AP8FU5=&%'5G!:,F@P
M3VI%,4U#53<*24<Q:&-M9'!B:3$P8C-!-DU$<V=B5T9Y6C)L=4Q72G9D2%)V
M8E1O=T]Y0G196$IN85<T=&)'5FUD1&]Y341S:5!J>'IC1T9U"DE(3C!E5WAL
M4%-*;6(R-3!,6$YP96U5-D]80C!/>4DK4$=:=F)N46=:;49J6E0P:7-B>31S
M:4DK2FTU:6,S03=*;35I8S-!-PI*;35I8S-!-TIM-6EC,T$W2FTU:6,S03=*
M;35I8S-!-TIM-6EC,T$W=6$W07AY04M)0T%G24-!9TE#06=)0T%G24-!9TE#
M06<*24-!9TE#06=/:41!>DQ0<GA,*S5W<E10>$UN07I,>DA)0V=W36EK,DUZ
M57A,5&,Q341!9TIM-6EC,T$W2FTU:6,S03=*;35I"F,S03=*;35I8S-!-TIM
M-6EC,T$W2FTU:6,S03=*;35I8S-!-V0R5FEB5T9Z9$=6>5%',6AA5WAW65A*
M,&)M5GE,;4YV3&UT>0I00SEM8C(U,%!J=W9C,T)H8FHT.$PS02M#:4%G24-!
M9TE#06=)0T%G24-!9TE#06=)0T%G4$,Y,%I$-$M)0T%G24-!9TE#06<*24-!
M9TE#06=)1'=V9$A)*T-G:TI#46M*241X1U0Q2DY)1S5H8E=5.4EM6G9C;3!Y
M26E":%DS4G!B,C0Y26TQ:&%7>#!B>G`S"EI72G196$XP6EA*06)71G!B2$)H
M8VY2=5I82759,CAU83-):4E'5G59,U(U8T=5.4EN4FQE2%%V8T=X:&%7-&E)
M1S%L9$=H=@I:1#!I8T<Y>F1#22M#:4%G24-!9TE#06=)0T%G24-!9TE#03AD
M2$DK0VE!9TE#06=)0T%G24-!9TE#06=)0T%G24-!9U!(4FL*24AD<%I(4F]0
M4TDR36I9:5!G;V=)0T%G24-!9TE#06=)0T%G24-!9TE#06=)0T%G24-!.&-$
M-&UB;4IZ8T1S;6)M2GIC1'-M"F)M2GIC1'-M8FU*>F-$<VUB;4IZ8T1S;6)M
M2GIC1'-M8FU*>F-$<VUB;4IZ8T1S;6)M2GIC1',X8S-":&)I0GID2&QS6E0P
M:0I:;3EU9$,Q>F%8<&Q/:FQW9$1S:5!S1$UU3C=!>GE!2TE#06=)0T%G24-!
M9TE#06=)0T%G24-!9TE#06=)0T%G24-!9TE-1%4*=#A)9TIM-6EC,T$W2FTU
M:6,S03=01VQU8TA6,$E(4C5C1U4Y26Y2;&5(46E)1S5H8E=5.4EM5G195VQS
M26E"=%E8:'-:5S5N"F1'9SE):E5W26E">F%8<&Q04TEZ34-)9V,S4C5B1U4Y
M26U*=F-M4FQC:3$S85=2,&%$;WA/>4)I8C-*:UI82719,CES8C-)-@I:,TIH
M951S9UEM.7E:1U9Y3%A.,&57>&Q/;DYV8D=L:T]Y22M00SEZ8T=&=5!G;TI#
M46M*0U%K2D-1:V=*;35I8S-!-TIM-6D*8S-!-U!'16=A2$IL6FHP:4EY26=B
M,C5J8D=L:F%Z,&EC,E9U6D=L,$M#:VE0:GAP8E=C9V,S2FI04TIO9$A2=T]I
M.'9D,V0S"DQM,6AA5WAW65A*,&)M5GE,;4YV3&UT>4PR5G195VQS3#)6=%E7
M;'-.:35N85=9:4E'2G9C;5)L8VHP:4U#26=95WAP6C(T.0I);4IV9$A2=F)3
M22M00SEH4&IW=F-$-$M)0T%G24-!9TE#06=)0T%G24-!9TE#06=)0T%G24-!
M9U!#.6UB,TIT4&=O9TE#06<*24-!9TE#06=)0T%G24-!9TE#06=)1'=V9$=1
M*T-I06=)0T%G24-!9TE#06=)0T%G24-!.$PS4GE09V]G24-!9TE#06=)0T%G
M"DE#03A,,U)H66UX;%!G;V=)0T%G24-!9TE$=W9D1U$K0VE!9TE#03A,,U)Y
M4&=O.$PS4FA9;7AL4&=O.&-#0FAB1VQN8FHP:0I9,E9U9$=6>4EJ-&UB;4IZ
M8T1S.$PS02M#:G=V66TY:V54-$M#:G=V84A2=&)$-$L*"BTM+2TM+3U?3F5X
M=%!A<G1?,#`P7S`Q,S=?,#%#,$8R,T$N.3-!,3%#,#`M+0H*"E]?7U]?7U]?
M7U]?7U]?7U]?7U]?7U]?7U]?7U]?7U]?7U]?7U]?7U]?7U]?7U]?"E!R;T94
M4$0@57-E<G,@3&ES=`H\<')O9G1P9"UU<V5R<T!P<F]F='!D+F]R9SX*:'1T
M<',Z+R]L:7-T<RYS;W5R8V5F;W)G92YN970O;&ES=',O;&ES=&EN9F\O<')O
+9G1P+75S97(*"@H`
`
end

-- System Information
Debian Release: 3.0
Kernel Version: Linux zewt.org 2.4.4-xfs #2 SMP Sun May 27 17:49:22 EDT 2001 i686 unknown

Versions of the packages mutt depends on:
ii  libc6          2.2.4-7        GNU C Library: Shared libraries and Timezone
ii  libncurses5    5.2.20010318-3 Shared libraries for terminal handling
ii  libsasl7       1.5.27-2       Authentication abstraction library.
rc  exim           3.03-5         Exim Mailer
ii  postfix        0.0.20011217.S A high-performance mail transport agent
	^^^ (Provides virtual package mail-transport-agent)



Information forwarded to debian-bugs-dist@lists.debian.org, Marco d'Itri <md@linux.it>:
Bug#126336; Package mutt. Full text and rfc822 format available.

Acknowledgement sent to Marco d'Itri <md@Linux.IT>:
Extra info received and forwarded to list. Copy sent to Marco d'Itri <md@linux.it>. Full text and rfc822 format available.

Message #10 received at 126336@bugs.debian.org (full text, mbox):

From: Marco d'Itri <md@Linux.IT>
To: Glenn Maynard <glenn@zewt.org>, 126336@bugs.debian.org
Subject: Re: Bug#126336: mutt: crash in index
Date: Mon, 24 Dec 2001 12:27:10 +0100
On Dec 24, Glenn Maynard <glenn@zewt.org> wrote:

 >A mail send to proftpd-users crashes mutt on my system.  I don't know if this
 >is exploitable, so I erred to caution; if this isn't fixed soon, but isn't
 >exploitable, change it to Normal.
I cannot reproduce this, which locale are you using?

 >(Tried to include core information; the script failed and stalled.)
Please run "gdb mutt core" and type "where" to get the full stack
trace.

-- 
ciao,
Marco



Noted your statement that Bug has been forwarded to mutt-dev@mutt.org. Request was from Marco d'Itri <md@linux.it> to control@bugs.debian.org. Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Marco d'Itri <md@linux.it>:
Bug#126336; Package mutt. Full text and rfc822 format available.

Acknowledgement sent to Marco d'Itri <md@Linux.IT>:
Extra info received and forwarded to list. Copy sent to Marco d'Itri <md@linux.it>. Full text and rfc822 format available.

Message #17 received at 126336@bugs.debian.org (full text, mbox):

From: Marco d'Itri <md@Linux.IT>
To: Glenn Maynard <glenn@zewt.org>, 126336@bugs.debian.org
Cc: control@bugs.debian.org
Subject: Re: Bug#126336: mutt: crash in index
Date: Fri, 28 Dec 2001 13:24:12 +0100
severity 126336 normal
thanks

I could not reproduce the bug and received no reply from mutt
developers, so I'm changing its severity to allow other bug fixes to go
in testing.

-- 
ciao,
Marco



Severity set to `normal'. Request was from Marco d'Itri <md@Linux.IT> to control@bugs.debian.org. Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Marco d'Itri <md@linux.it>:
Bug#126336; Package mutt. Full text and rfc822 format available.

Acknowledgement sent to Glenn Maynard <glenn@zewt.org>:
Extra info received and forwarded to list. Copy sent to Marco d'Itri <md@linux.it>. Full text and rfc822 format available.

Message #24 received at 126336@bugs.debian.org (full text, mbox):

From: Glenn Maynard <glenn@zewt.org>
To: 126336@bugs.debian.org
Subject: cols
Date: Fri, 28 Dec 2001 15:14:34 -0500
Terminal size appears to matter.  It only happens when my terminal is
145 columns or greater in UTF-8 mode (with the locale generated, of
course.)  This has been reproduced on another machine.

-- 
Glenn Maynard



Information forwarded to debian-bugs-dist@lists.debian.org, Marco d'Itri <md@linux.it>, mutt@packages.qa.debian.org:
Bug#126336; Package mutt. Full text and rfc822 format available.

Acknowledgement sent to Glenn Maynard <glenn@zewt.org>:
Extra info received and forwarded to list. Copy sent to Marco d'Itri <md@linux.it>, mutt@packages.qa.debian.org. Full text and rfc822 format available.

Message #29 received at 126336@bugs.debian.org (full text, mbox):

From: Glenn Maynard <glenn@zewt.org>
To: 126336@bugs.debian.org
Subject: still there, still reproducable, happened twice again
Date: Fri, 18 Jan 2002 16:55:02 -0500
Two more spams have crashed Mutt; one of them is at ftp://zewt.org/p2.
Again, seems to need an UTF-8 locale and a wide (~120+ column) terminal.
This happens with both mutt and mutt-utf8 in unstable.

-- 
Glenn Maynard



Information forwarded to debian-bugs-dist@lists.debian.org, Marco d'Itri <md@linux.it>, mutt@packages.qa.debian.org:
Bug#126336; Package mutt. Full text and rfc822 format available.

Acknowledgement sent to Glenn Maynard <g_deb@zewt.org>:
Extra info received and forwarded to list. Copy sent to Marco d'Itri <md@linux.it>, mutt@packages.qa.debian.org. Full text and rfc822 format available.

Message #34 received at 126336@bugs.debian.org (full text, mbox):

From: Glenn Maynard <g_deb@zewt.org>
To: debian-devel@lists.debian.org
Cc: 126336@bugs.debian.org
Subject: Re: *elide*
Date: Mon, 28 Jan 2002 22:06:00 -0500
On Tue, Jan 29, 2002 at 09:42:00AM +0900, ������ wrote:
> (Korean spam)

Now a posting to debian-devel (Message-ID: <IY8pXD.A.E-E.iAfV8@murphy>)
is triggering this bug.  Can anyone else reproduce this?  Install mutt-utf8,
set LANG=en_US.UTF-8 (and generate it--I wish locale-gen would always
generate UTF-8 locales), make your terminal wide (around 140-150 columns)
and load debian-devel.  It segfaults for me merely by displaying it in the
index.

I'm not sure if this is exploitable; I did report it as important but it
was downgraded to normal.  It's definitely smashing the stack, though
any exploit might be dependent on the terminal width or need to two-way
through another encoding and/or be valid UTF-8, so I'm not terribly
concerned.

This might be yet another occurance of slang1-utf8 weirdness.

-- 
Glenn Maynard



Merged 126336 133597. Request was from Marco d'Itri <md@Linux.IT> to control@bugs.debian.org. Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Marco d'Itri <md@linux.it>, mutt@packages.qa.debian.org:
Bug#126336; Package mutt. Full text and rfc822 format available.

Acknowledgement sent to Glenn Maynard <glenn@zewt.org>:
Extra info received and forwarded to list. Copy sent to Marco d'Itri <md@linux.it>, mutt@packages.qa.debian.org. Full text and rfc822 format available.

Message #41 received at 126336@bugs.debian.org (full text, mbox):

From: Glenn Maynard <glenn@zewt.org>
To: 126336@bugs.debian.org, control@bugs.debian.org
Subject: fixed in CVS.
Date: Mon, 1 Apr 2002 16:13:55 -0500
[Message part 1 (text/plain, inline)]
tag 126336 patch
thanks

This is fixed in CVS.  If it's not in a stable release (or if you're not
updating to it before woody), I'd suggest applying Edmund's patch.

-- 
Glenn Maynard
[diff (text/plain, attachment)]

Tags added: patch Request was from Glenn Maynard <glenn@zewt.org> to control@bugs.debian.org. Full text and rfc822 format available.

Reply sent to Marco d'Itri <md@linux.it>:
You have taken responsibility. Full text and rfc822 format available.

Notification sent to Glenn Maynard <glenn@zewt.org>:
Bug acknowledged by developer. Full text and rfc822 format available.

Message #48 received at 126336-close@bugs.debian.org (full text, mbox):

From: Marco d'Itri <md@linux.it>
To: 126336-close@bugs.debian.org
Subject: Bug#126336: fixed in mutt 1.3.28-2
Date: Thu, 11 Apr 2002 12:20:04 -0400
We believe that the bug you reported is fixed in the latest version of
mutt, which is due to be installed in the Debian FTP archive:

mutt-utf8_1.3.28-2_i386.deb
  to pool/main/m/mutt/mutt-utf8_1.3.28-2_i386.deb
mutt_1.3.28-2.diff.gz
  to pool/main/m/mutt/mutt_1.3.28-2.diff.gz
mutt_1.3.28-2.dsc
  to pool/main/m/mutt/mutt_1.3.28-2.dsc
mutt_1.3.28-2_i386.deb
  to pool/main/m/mutt/mutt_1.3.28-2_i386.deb
mutt_1.3.28.orig.tar.gz
  to pool/main/m/mutt/mutt_1.3.28.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 126336@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Marco d'Itri <md@linux.it> (supplier of updated mutt package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sat,  6 Apr 2002 18:35:01 +0200
Source: mutt
Binary: mutt mutt-utf8
Architecture: source i386
Version: 1.3.28-2
Distribution: unstable
Urgency: medium
Maintainer: Marco d'Itri <md@linux.it>
Changed-By: Marco d'Itri <md@linux.it>
Description: 
 mutt       - Text-based mailreader supporting MIME, GPG, PGP and threading.
 mutt-utf8  - Text-based mailreader supporting MIME, GPG, PGP and threading.
Closes: 126336 140970
Changes: 
 mutt (1.3.28-2) unstable; urgency=medium
 .
   * Moved into main.
   * Suggests: libgcrypt1, gnutls3 (Closes: #140970).
   * Added patch from CVS to fix crash with UTF-8 locales (Closes: #126336).
Files: 
 47707e751d4252ecd84396c7cc29a1c2 755 mail standard mutt_1.3.28-2.dsc
 015e4fce09e323997d64ad455524be19 2540330 mail standard mutt_1.3.28.orig.tar.gz
 989c120b389a32105d67960090e7e9a8 49993 mail standard mutt_1.3.28-2.diff.gz
 93a62a3884eed74ae70bacc6fb98e6b3 1301592 mail standard mutt_1.3.28-2_i386.deb
 12f04eacb749f47e6bb794d17ca739a1 360842 mail optional mutt-utf8_1.3.28-2_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://gnupg.linux.it

iD8DBQE8ryZrFGfw2OHuP7ERAvmhAJ9UXBj/XpnTjAPvVWYVMGOhp1TxWwCeMEB1
bpWfH06B7MtfEfm0NFqFfik=
=2ibm
-----END PGP SIGNATURE-----




Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Apr 20 03:53:16 2014; Machine Name: buxtehude.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.