CVE-2021-44143: Critical severity isync vulnerability
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44143?
CVE-2021-44143 has been classified with high severity due to the potential for a heap overflow vulnerability.
How do I fix CVE-2021-44143?
To fix CVE-2021-44143, upgrade isync to version 1.4.4-5 or later.
Which versions of isync are affected by CVE-2021-44143?
CVE-2021-44143 affects isync versions from 1.4.0 to 1.4.3.
What are the potential impacts of CVE-2021-44143?
Exploitation of CVE-2021-44143 could lead to remote code execution through a crafted mail message.
Can I use Debian or Fedora systems with isync affected by CVE-2021-44143?
Yes, Debian systems running versions 9.0, 10.0, 11.0 and Fedora versions 34, 35 are affected by CVE-2021-44143.