CVE-2021-20247
Summary
| CVE | CVE-2021-20247 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 19:15:00 UTC |
| Updated | 2023-11-07 03:29:00 UTC |
| Description | A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1928963 – (CVE-2021-20247) CVE-2021-20247 isync/mbsync: mailbox names returned by IMAP LIST/LSUB not validated |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 32 Update: isync-1.4.1-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| isync: Multiple Vulnerabilities (GLSA 202208-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| oss-security - CVE-2021-20247: isync/mbsync data leak/destruction vulnerability |
MISC |
www.openwall.com |
Exploit, Mailing List, Third Party Advisory |
| [SECURITY] Fedora 32 Update: isync-1.4.1-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 33 Update: isync-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 3066-1] isync security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 33 Update: isync-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179393 Debian Security Update for isync (CVE-2021-20247)
- 180384 Debian Security Update for isync (DLA 3066-1)
- 281601 Fedora Security Update for isync (FEDORA-2021-954ebabcf7)
- 281602 Fedora Security Update for isync (FEDORA-2021-ef8c2acfce)
- 501585 Alpine Linux Security Update for isync
- 501869 Alpine Linux Security Update for isync
- 710592 Gentoo Linux isync Multiple Vulnerabilities (GLSA 202208-15)
- 750281 OpenSUSE Security Update for isync (openSUSE-SU-2021:0516-1)