Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3657

Опубликовано: 18 фев. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:isync_project:isync:*:*:*:*:*:*:*:*
Версия до 1.4.4 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06799
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119
CWE-119

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.

CVSS3: 9.8
debian
почти 4 года назад

A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate ...

CVSS3: 9.8
github
почти 4 года назад

A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.

EPSS

Процентиль: 91%
0.06799
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-119
CWE-119