First published: Sun Jan 17 2021(Updated: )
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mutt | 1.10.1-2.1+deb10u6 1.10.1-2.1+deb10u7 2.0.5-4.1+deb11u3 2.2.12-0.1~deb12u1 2.2.9-1+deb12u1 2.2.12-0.1 | |
Mutt Mutt | <=2.0.4 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
debian/mutt | <=1.10.1-2.1+deb10u4<=1.10.1-1<=2.0.2-1 | 2.0.5-1 1.10.1-2.1+deb10u5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-3181.
The severity of CVE-2021-3181 is high.
CVE-2021-3181 allows remote attackers to cause a denial of service (mailbox unavailability) in Mutt.
Mutt versions up to and including 2.0.4 are affected by CVE-2021-3181.
To fix CVE-2021-3181, update Mutt to version 2.0.5-1 or apply the recommended patches from the vendor.