CVE-2021-3657
18.02.2022, 18:15
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
isync_project | isync | 𝑥 < 1.4.4 |
redhat | enterprise_linux | 7.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References