First published: Thu Jun 03 2021(Updated: )
A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Isync Project Isync | <1.3.6 | |
Isync Project Isync | =1.4.0 | |
Isync Project Isync | =1.4.1 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Debian Debian Linux | =9.0 | |
redhat/isync | <1.3.6 | 1.3.6 |
redhat/isync | <1.4.2 | 1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.