CVE-2021-32055
05.05.2021, 16:15
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mutt | mutt | 1.11.0 ≤ 𝑥 < 2.0.7 |
| neomutt | neomutt | 20191025 ≤ 𝑥 ≤ 20210504 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mutt |
| ||||||||||||||||
| neomutt |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mutt |
| ||||||||||||||||||||||||
| neomutt |
|
Common Weakness Enumeration
References