CVE-2021-32055
Published: 5 May 2021
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.
Priority
Status
Package | Release | Status |
---|---|---|
mutt Launchpad, Ubuntu, Debian |
jammy |
Not vulnerable
(2.0.5-4.1)
|
impish |
Not vulnerable
(2.0.5-4.1)
|
|
bionic |
Not vulnerable
(code not present)
|
|
upstream |
Needs triage
|
|
hirsute |
Ignored
(end of life)
|
|
focal |
Released
(1.13.2-1ubuntu0.5)
|
|
groovy |
Ignored
(end of life)
|
|
trusty |
Does not exist
|
|
xenial |
Released
(1.5.24-1ubuntu0.6+esm2)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
kinetic |
Not vulnerable
(2.0.5-4.1)
|
|
lunar |
Not vulnerable
(2.0.5-4.1)
|
|
neomutt Launchpad, Ubuntu, Debian |
jammy |
Needs triage
|
impish |
Ignored
(end of life)
|
|
kinetic |
Ignored
(end of life, was needs-triage)
|
|
trusty |
Ignored
(end of standard support)
|
|
xenial |
Ignored
(end of standard support)
|
|
bionic |
Needs triage
|
|
focal |
Needs triage
|
|
upstream |
Needs triage
|
|
hirsute |
Ignored
(end of life)
|
|
groovy |
Ignored
(end of life)
|
|
lunar |
Needs triage
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.1 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32055
- https://gitlab.com/muttmua/mutt/-/commit/7c4779ac24d2fb68a2a47b58c7904118f40965d5
- https://github.com/neomutt/neomutt/commit/fa1db5785e5cfd9d3cd27b7571b9fe268d2ec2dc
- http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20210503/000036.html
- https://ubuntu.com/security/notices/USN-5392-1
- NVD
- Launchpad
- Debian