Vulnerability CVE-2021-32055: Information
Description
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.
Severity: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
mutt | sisyphus | 2.1.1.0.3.g6c0f75cca-alt1 | 2.1.1.0.3.g6c0f75cca-alt1 | ALT-PU-2021-2337-1 | 280824 | Fixed |
mutt | p10 | 2.1.1.0.3.g6c0f75cca-alt1 | 2.1.1.0.3.g6c0f75cca-alt1 | ALT-PU-2021-2359-1 | 280830 | Fixed |
mutt | c10f1 | 2.1.1.0.3.g6c0f75cca-alt1 | 2.1.1.0.3.g6c0f75cca-alt1 | ALT-PU-2021-2359-1 | 280830 | Fixed |
neomutt | sisyphus | 20210205-alt2 | 20240329-alt1 | ALT-PU-2021-2140-1 | 277283 | Fixed |
neomutt | p10 | 20210205-alt2 | 20210205-alt2 | ALT-PU-2021-2140-1 | 277283 | Fixed |
neomutt | p9 | 20210205-alt2 | 20210205-alt2 | ALT-PU-2021-2158-1 | 277285 | Fixed |
neomutt | c10f1 | 20210205-alt2 | 20210205-alt2 | ALT-PU-2021-2140-1 | 277283 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://gitlab.com/muttmua/mutt/-/commit/7c4779ac24d2fb68a2a47b58c7904118f40965d5 |
|
http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20210503/000036.html |
|
https://github.com/neomutt/neomutt/commit/fa1db5785e5cfd9d3cd27b7571b9fe268d2ec2dc |
|
GLSA-202105-05 |
|