CVE-2021-3657
published 2022-02-18CVE-2021-3657: A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.46%
87.8th percentile
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | isync | < isync 1.4.4-1 (bookworm) | isync 1.4.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| isync_project | isync | < 1.4.4 | 1.4.4 |
| isync_project | isync | — | — |
| isync_project | isync | >= 0 < 1.3.0-2.2+deb11u1 | 1.3.0-2.2+deb11u1 |
| isync_project | isync | >= 0 < 1.4.4-1 | 1.4.4-1 |
| isync_project | isync | >= 0 < 1.4.4-1 | 1.4.4-1 |
| isync_project | isync | >= 0 < 1.4.4-1 | 1.4.4-1 |
| redhat | enterprise_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target application is mbsync (isync); flag versions prior to 1.4.4 as vulnerable to buffer overflow via oversized IMAP literals ↗
- →Monitor IMAP traffic for unusually large (>=2GiB) literal size values in server responses, which could indicate exploitation attempts against vulnerable mbsync clients ↗
- ·Vulnerability can be triggered not only by malicious IMAP servers but also hypothetically by external email senders, broadening the attack surface beyond just the configured mail server ↗
- ·Debian scoped this as 'local' impact; fixed versions per distro: bookworm/forky/sid/trixie fixed in 1.4.4-1, bullseye fixed in 1.3.0-2.2+deb11u1 ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gq8r-4g7c-69vw: A flaw was found in mbsync versions prior to 1
ghsa_unreviewed·2022-02-19
CVE-2021-3657 [CRITICAL] CWE-119 GHSA-gq8r-4g7c-69vw: A flaw was found in mbsync versions prior to 1
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
OSV
CVE-2021-3657: A flaw was found in mbsync versions prior to 1
osv·2022-02-18·CVSS 9.8
CVE-2021-3657 [CRITICAL] CVE-2021-3657: A flaw was found in mbsync versions prior to 1
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
Debian
CVE-2021-3657: isync - A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling o...
vendor_debian·2021·CVSS 9.8
CVE-2021-3657 [CRITICAL] CVE-2021-3657: isync - A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling o...
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.3.0-2.2+deb11u1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2028932https://lists.debian.org/debian-lts-announce/2022/07/msg00001.htmlhttps://security.gentoo.org/glsa/202208-15https://www.openwall.com/lists/oss-security/2021/12/03/1https://bugzilla.redhat.com/show_bug.cgi?id=2028932https://lists.debian.org/debian-lts-announce/2022/07/msg00001.htmlhttps://security.gentoo.org/glsa/202208-15https://www.openwall.com/lists/oss-security/2021/12/03/1
2022-02-18
Published