← Back

CVE-2021-3657

nvd nist
Published: Feb 18, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.

Affected (4)

Show all products
1 product
Isync
1 product
Fedora
1 product
Enterprise Linux
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (8)

Source: patrick@puiterwijk.org
Issue TrackingThird Party Advisory
Source: patrick@puiterwijk.org
Mailing ListThird Party Advisory
Source: patrick@puiterwijk.org
Third Party Advisory
Source: patrick@puiterwijk.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.