PT-2021-3694 · Mailutils+5 · Mailutils+5

Jakub Żoczek

·

Published

2021-07-16

·

Updated

2025-10-28

·

CVE-2021-32749

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions fail2ban versions 0.9.7 and prior fail2ban versions 0.10.0 through 0.10.6 fail2ban versions 0.11.0 through 0.11.2
Description The issue is related to errors in the mail-whois function. It leads to possible remote code execution in the mailing action mail-whois. The command mail from the mailutils package used in mail actions like mail-whois can execute commands if unescaped sequences ( ~) are available in the "foreign" input, for instance in whois output. To exploit the issue, an attacker would need to insert malicious characters into the response sent by the whois server, either via a MITM attack or by taking over a whois server.
Recommendations For versions 0.9.7 and prior, update to a version newer than 0.9.7 or patch the vulnerability manually. For versions 0.10.0 through 0.10.6, update to version 0.10.7 or patch the vulnerability manually. For versions 0.11.0 through 0.11.2, update to version 0.11.3 or patch the vulnerability manually. As a temporary workaround, consider avoiding the usage of the action mail-whois until the issue is resolved.

Exploit

Fix

RCE

OS Command Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2836
ALT-PU-2021-2873
ALT-PU-2022-2862
ALT-PU-2025-13255
BDU:2021-03927
CVE-2021-32749
GHSA-M985-3F3V-CWMM
MGASA-2021-0464
OPENSUSE-SU-2021:1274-1
OPENSUSE-SU-2021_1274-1
OPENSUSE-SU-2024:10749-1
USN-5232-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Fail2Ban
Mailutils