Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.
Exploitability
AV:LAC:HAu:SImpact
C:PI:PA:P3.5/AV:L/AC:H/Au:S/C:P/I:P/A:P