CVE-2021-3657
Summary
| CVE | CVE-2021-3657 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-18 18:15:00 UTC |
| Updated | 2022-12-21 15:01:00 UTC |
| Description | A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 2028932 – (CVE-2021-3657) CVE-2021-3657 isync: buffer overflows due to inadequate handling of extremely large IMAP literals |
MISC |
bugzilla.redhat.com |
|
| isync: Multiple Vulnerabilities (GLSA 202208-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| oss-security - CVE-2021-3657: multiple buffer overflows in isync/mbsync |
MISC |
www.openwall.com |
|
| [SECURITY] [DLA 3066-1] isync security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179737 Debian Security Update for isync (CVE-2021-3657)
- 180384 Debian Security Update for isync (DLA 3066-1)
- 282098 Fedora Security Update for isync (FEDORA-2021-577129851b)
- 282123 Fedora Security Update for isync (FEDORA-2021-b7fdb7e69a)
- 502104 Alpine Linux Security Update for isync
- 504954 Alpine Linux Security Update for isync
- 710592 Gentoo Linux isync Multiple Vulnerabilities (GLSA 202208-15)