Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3578

Опубликовано: 16 фев. 2022
Источник: debian

Описание

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
isyncfixed1.3.0-2.2package
isyncfixed1.3.0-2.2~deb10u1busterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2021/06/07/1

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

CVSS3: 7.8
nvd
почти 4 года назад

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

suse-cvrf
больше 4 лет назад

Security update for isync

CVSS3: 7.8
github
почти 4 года назад

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.