cbcvebase.
CVE-2021-3657
published 2022-02-18

CVE-2021-3657: A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.46%
87.8th percentile
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianisync< isync 1.4.4-1 (bookworm)isync 1.4.4-1 (bookworm)
fedoraprojectfedora
isync_projectisync< 1.4.41.4.4
isync_projectisync
isync_projectisync>= 0 < 1.3.0-2.2+deb11u11.3.0-2.2+deb11u1
isync_projectisync>= 0 < 1.4.4-11.4.4-1
isync_projectisync>= 0 < 1.4.4-11.4.4-1
isync_projectisync>= 0 < 1.4.4-11.4.4-1
redhatenterprise_linux

Detection & IOCsextracted from sources · hover to see the quote

  • Target application is mbsync (isync); flag versions prior to 1.4.4 as vulnerable to buffer overflow via oversized IMAP literals
  • Monitor IMAP traffic for unusually large (>=2GiB) literal size values in server responses, which could indicate exploitation attempts against vulnerable mbsync clients
  • ·Vulnerability can be triggered not only by malicious IMAP servers but also hypothetically by external email senders, broadening the attack surface beyond just the configured mail server
  • ·Debian scoped this as 'local' impact; fixed versions per distro: bookworm/forky/sid/trixie fixed in 1.4.4-1, bullseye fixed in 1.3.0-2.2+deb11u1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.