CVE-2021-32055
Summary
| CVE | CVE-2021-32055 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-05 16:15:00 UTC |
| Updated | 2021-06-01 14:52:00 UTC |
| Description | Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix seqset iterator when it ends in a comma · neomutt/neomutt@fa1db57 · GitHub | MISC | github.com | |
| Fix seqset iterator when it ends in a comma. (7c4779ac) · Commits · Mutt Project / mutt · GitLab | MISC | gitlab.com | |
| Mutt, NeoMutt: Denial of Service (GLSA 202105-05) — Gentoo security | GENTOO | security.gentoo.org | |
| mutt 2.0.7 released | MISC | lists.mutt.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179622 Debian Security Update for muttneomutt (CVE-2021-32055)
- 198757 Ubuntu Security Notification for Mutt Vulnerabilities (USN-5392-1)
- 296053 Oracle Solaris 11.4 Support Repository Update (SRU) 35.94.4 Missing (CPUJUL2021)
- 502890 Alpine Linux Security Update for neomutt
- 505768 Alpine Linux Security Update for neomutt
- 710110 Gentoo Linux Mutt, NeoMutt Denial of service vulnerability (GLSA 202105-05)
- 901922 Common Base Linux Mariner (CBL-Mariner) Security Update for mutt (7292)
- 904636 Common Base Linux Mariner (CBL-Mariner) Security Update for mutt (7292-1)