CVE-2021-3657

CRITICAL

isync < 1.4.4 - Remote Code Execution via Large IMAP Literal Handling

Title source: llm
STIX 2.1

Description

A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.

References (4)

Core 4
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2028932
Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2021/12/03/1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/07/msg00001.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202208-15

Scores

CVSS v3 9.8
EPSS 0.0575
EPSS Percentile 90.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (4)
debian/debian_linux 9.0
fedoraproject/fedora 35
isync_project/isync < 1.4.4
redhat/enterprise_linux 7.0
Published Feb 18, 2022
Tracked Since Feb 18, 2026