Put this email in a maildir (mkdir crash crash/{cur,new.tmp}, cat >crash/new/foo) and try to open it in mutt.
Mutt will crash every time, saying "*** glibc detected *** mutt: double free or corruption (!prev): 0x00000000018e21d0 ***" Most of the message is obscured by ncurses. Running intrepid, mutt 1.5.18-4ubuntu1. Might be hard to exploit, as glibc is explicitly triggering an abort, but still might be doable, or same bug could cause other corruption.
Return-Path: <email address hidden>
Received: from 152.209.104.58 by ; Thu, 15 Jan 2009 16:44:52 +0200
Message-ID: <H[20
Date: Wed, 14 Jan 2009 22:34:28 +0000 (UTC)
From: <email address hidden>
To: undisclosed-recipients:;
Binary package hint: mutt
Put this email in a maildir (mkdir crash crash/{ cur,new. tmp}, cat >crash/new/foo) and try to open it in mutt.
Mutt will crash every time, saying "*** glibc detected *** mutt: double free or corruption (!prev): 0x00000000018e21d0 ***" Most of the message is obscured by ncurses. Running intrepid, mutt 1.5.18-4ubuntu1. Might be hard to exploit, as glibc is explicitly triggering an abort, but still might be doable, or same bug could cause other corruption.
Return-Path: <email address hidden> recipients: ;
Received: from 152.209.104.58 by ; Thu, 15 Jan 2009 16:44:52 +0200
Message-ID: <H[20
Date: Wed, 14 Jan 2009 22:34:28 +0000 (UTC)
From: <email address hidden>
To: undisclosed-