CVE-2021-3657: Buffer Overflow
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3657?
CVE-2021-3657 has a high severity due to the potential for buffer overflows that could lead to code execution.
How do I fix CVE-2021-3657?
To fix CVE-2021-3657, upgrade mbsync to version 1.4.4 or higher.
What versions of isync are affected by CVE-2021-3657?
Versions of isync prior to 1.4.4 are affected by CVE-2021-3657.
Can CVE-2021-3657 be exploited remotely?
Yes, CVE-2021-3657 can potentially be exploited by malicious IMAP servers or external email senders.
What platforms are impacted by CVE-2021-3657?
CVE-2021-3657 impacts systems running affected versions of isync on various platforms including Red Hat, Debian, and Fedora.