CVE-2021-3181
Summary
| CVE | CVE-2021-3181 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-19 15:15:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - glibc iconv crash with ISO-2022-JP-3 |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| Mutt: Denial of service (GLSA 202101-25) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Don't allocate a group terminator unless we are in a group-list. (939b02b3) · Commits · Mutt Project / mutt · GitLab |
MISC |
gitlab.com |
Patch, Third Party Advisory |
| [SECURITY] [DLA 2529-1] mutt security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 33 Update: mutt-2.0.5-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: mutt-2.0.5-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Add group terminator if it is left off. (d4305208) · Commits · Mutt Project / mutt · GitLab |
MISC |
gitlab.com |
Patch, Third Party Advisory |
| oss-security - Re: mutt recipient parsing memory leak |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| rfc822 group recipient parsing leaks memory (#323) · Issues · Mutt Project / mutt · GitLab |
MISC |
gitlab.com |
Third Party Advisory |
| [SECURITY] Fedora 33 Update: mutt-2.0.5-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Fix memory leak parsing group addresses without a display name. (4a2becbd) · Commits · Mutt Project / mutt · GitLab |
MISC |
gitlab.com |
Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4838-1 mutt |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: mutt-2.0.5-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159902 Oracle Enterprise Linux Security Update for mutt (ELSA-2021-4181)
- 180230 Debian Security Update for mutt (CVE-2021-3181)
- 239818 Red Hat Update for mutt security (RHSA-2021:4181)
- 296067 Oracle Solaris 11.4 Support Repository Update (SRU) 33.94.0 Missing (CPUAPR2021)
- 354118 Amazon Linux Security Advisory for mutt : ALAS2-2022-1892
- 501088 Alpine Linux Security Update for mutt
- 501633 Alpine Linux Security Update for mutt
- 670257 EulerOS Security Update for mutt (EulerOS-SA-2021-1819)
- 670465 EulerOS Security Update for mutt (EulerOS-SA-2021-2224)
- 670651 EulerOS Security Update for mutt (EulerOS-SA-2021-2409)
- 670941 EulerOS Security Update for mutt (EulerOS-SA-2021-2224)
- 690430 Free Berkeley Software Distribution (FreeBSD) Security Update for mutt (387bbade-5d1d-11eb-bf20-4437e6ad11c4)
- 750391 OpenSUSE Security Update for mutt (openSUSE-SU-2021:0162-1)
- 750392 OpenSUSE Security Update for mutt (openSUSE-SU-2021:0161-1)
- 940384 AlmaLinux Security Update for mutt (ALSA-2021:4181)
- 960372 Rocky Linux Security Update for mutt (RLSA-2021:4181)