mutt is vulnerable to denial of service. A remote attacker is able to cause a denial of service condition resulting in mailbox unavailability by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups), causing large memory consumption.
www.openwall.com/lists/oss-security/2021/01/19/10
www.openwall.com/lists/oss-security/2021/01/27/3
gitlab.com/muttmua/mutt/-/commit/4a2becbdb4422aaffe3ce314991b9d670b7adf17
gitlab.com/muttmua/mutt/-/commit/939b02b33ae29bc0d642570c1dcfd4b339037d19
gitlab.com/muttmua/mutt/-/commit/d4305208955c5cdd9fe96dfa61e7c1e14e176a14
gitlab.com/muttmua/mutt/-/issues/323
lists.debian.org/debian-lts-announce/2021/01/msg00017.html
lists.fedoraproject.org/archives/list/[email protected]/message/DXGWXFO77HBCD3VYEIYHHYU33LYWWWNQ/
lists.fedoraproject.org/archives/list/[email protected]/message/P2OMLQKAOHPYQA4GI7ZUO6UKCPUHLYO7/
security-tracker.debian.org/tracker/CVE-2021-3181
security.gentoo.org/glsa/202101-25
www.debian.org/security/2021/dsa-4838