CVE-2021-32055
05.05.2021, 16:15
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.Enginsight
Vendor | Product | Version |
---|---|---|
mutt | mutt | 1.11.0 ≤ 𝑥 < 2.0.7 |
neomutt | neomutt | 20191025 ≤ 𝑥 ≤ 20210504 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mutt |
| ||||||||||||||||
neomutt |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mutt |
| ||||||||||||||||||||||||
neomutt |
|
Common Weakness Enumeration
References