PT-2021-13854 · Mbsync+1 · Mbsync+1

Pedro Sampaio

·

Published

2021-02-23

·

Updated

2024-06-15

·

CVE-2021-20247

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: mbsync versions prior to 1.3.5 and 1.4.1
Description: A flaw was found in mbsync where validations of the mailbox names returned by IMAP LIST/LSUB do not occur, allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity.
Recommendations: For mbsync versions prior to 1.3.5, update to version 1.3.5 or later. For mbsync versions prior to 1.4.1, update to version 1.4.1 or later. As a temporary workaround, consider restricting access to the IMAP LIST/LSUB functionality until a patch is available.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20247
DLA-3066-1
OPENSUSE-SU-2021:0516-1
OPENSUSE-SU-2021:0533-1
OPENSUSE-SU-2021_0516-1
OPENSUSE-SU-2024:10866-1

Affected Products

Suse
Mbsync