cbcvebase.
CVE-2021-3657
published 2022-02-18

CVE-2021-3657: A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianisync< isync 1.4.4-1 (bookworm)isync 1.4.4-1 (bookworm)
fedoraprojectfedora
isync_projectisync< 1.4.41.4.4
isync_projectisync
isync_projectisync>= 0 < 1.3.0-2.2+deb11u11.3.0-2.2+deb11u1
isync_projectisync>= 0 < 1.4.4-11.4.4-1
isync_projectisync>= 0 < 1.4.4-11.4.4-1
isync_projectisync>= 0 < 1.4.4-11.4.4-1
redhatenterprise_linux

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL