CVE-2021-38370Command Injection in Project Alpine

CWE-77Command Injection6 documents5 sources
Severity
5.9MEDIUMNVD
OSV7.5
EPSS
0.4%
top 40.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 10
Latest updateMar 20

Description

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/alpine< alpine 2.25+dfsg1-1 (bookworm)
Debianalpine_project/alpine< 2.25+dfsg1-1+2
Ubuntualpine_project/alpine< 2.20+dfsg1-2ubuntu0.1~esm1+2

🔴Vulnerability Details

3
OSV
alpine vulnerabilities2025-03-20
GHSA
GHSA-2c2h-qvww-cw95: In Alpine through 22022-05-24
OSV
CVE-2021-38370: In Alpine before 22021-08-10

📋Vendor Advisories

2
Ubuntu
Alpine vulnerabilities2025-03-20
Debian
CVE-2021-38370: alpine - In Alpine before 2.25, untagged responses from an IMAP server are accepted befor...2021