CVE-2021-46853: Medium severity alpine vulnerability
Published Nov 3, 2022
·Updated
Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
Affected Software
2 affected componentsFixes available
Alpine Project Alpine<2.25
debian/alpine<=2.24+dfsg1-1
2.26+dfsg-12.26+dfsg-2
Event History
Nov 3, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityAffected Software
Mar 20, 2025
Data Sourced
via Debian·03:03 AM
DescriptionAffected Software
Data Sourced
via Launchpad·03:03 AM
Description
Mar 24, 2025
Data Sourced
via Ubuntu·03:03 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Alpine vulnerability?
The vulnerability ID for this Alpine vulnerability is CVE-2021-46853.
2
What is the severity of CVE-2021-46853?
The severity of CVE-2021-46853 is medium with a CVSS score of 5.9.
3
How does CVE-2021-46853 impact Alpine?
CVE-2021-46853 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
4
Which version of Alpine is affected by CVE-2021-46853?
Alpine version up to and excluding 2.25 is affected by CVE-2021-46853.
5
How can I fix CVE-2021-46853 in Alpine?
To fix CVE-2021-46853 in Alpine, it is recommended to update to version 2.25 or later.