PT-2022-10520 · Mbsync+1 · Mbsync+1

Oswald Buddenhagen

·

Published

2022-02-18

·

Updated

2024-11-25

·

CVE-2021-3657

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mbsync versions prior to 1.4.4
Description A flaw was found due to inadequate handling of extremely large (>=2GiB) IMAP literals. Malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to IMAP servers to minimize the risk of exploitation. Avoid using mbsync with untrusted or potentially compromised IMAP servers until the issue is resolved.

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15885
ALT-PU-2024-16028
CVE-2021-3657
DLA-3066-1
OPENSUSE-SU-2024:11779-1

Affected Products

Alt Linux
Mbsync