First published: Fri Dec 03 2021(Updated: )
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution. Reference: <a href="https://www.openwall.com/lists/oss-security/2021/12/03/1">https://www.openwall.com/lists/oss-security/2021/12/03/1</a>
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Isync Project Isync | <1.4.4 | |
Fedoraproject Fedora | =35 | |
Redhat Enterprise Linux | =7.0 | |
Debian Debian Linux | =9.0 | |
redhat/isync | <1.4.4 | 1.4.4 |
debian/isync | 1.3.0-2.2+deb11u1 1.4.4-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.