CVE-2021-38370: Command Injection
Published Aug 10, 2021
·Updated
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
Affected Software
2 affected componentsFixes available
Alpine Project Alpine<2.25
debian/alpine<=2.24+dfsg1-1
2.26+dfsg-12.26+dfsg-2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/alpineto a version that resolves this vulnerability.Fixed in 2.26+dfsg-1Fixed in 2.26+dfsg-2
Event History
Aug 10, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 20, 2025
Data Sourced
via Launchpad·03:03 AM
Description
Data Sourced
via Debian·03:03 AM
DescriptionAffected Software
Mar 24, 2025
Data Sourced
via Ubuntu·03:03 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Alpine issue?
The vulnerability ID for this Alpine issue is CVE-2021-38370.
2
What is the severity of CVE-2021-38370?
CVE-2021-38370 has a severity rating of medium (5.9).
3
What is the impact of CVE-2021-38370?
CVE-2021-38370 allows untagged responses from an IMAP server to be accepted before STARTTLS, which can result in unauthorized access to sensitive information.
4
What is the affected software for CVE-2021-38370?
The affected software for CVE-2021-38370 is Alpine version up to (exclusive) 2.25.
5
Is there a fix available for CVE-2021-38370?
Yes, updating Alpine to version 2.25 or later will fix CVE-2021-38370.