CVE-2021-3578: Incorrect Type Cast
A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3578?
CVE-2021-3578 is rated as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2021-3578?
To fix CVE-2021-3578, upgrade mbsync to versions 1.3.6 or 1.4.2 and above.
Which versions of isync are affected by CVE-2021-3578?
CVE-2021-3578 affects isync versions prior to 1.3.6 and versions 1.4.0 and 1.4.1.
Can CVE-2021-3578 be exploited remotely?
Yes, CVE-2021-3578 can be exploited by a malicious server issuing an unexpected APPENDUID response.
What systems are impacted by CVE-2021-3578?
CVE-2021-3578 impacts systems using affected versions of isync across multiple Linux distributions like Red Hat and Debian.