CVE-2021-44143 Information
Description
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e. one that starts with an empty line) to provoke a heap overflow which could conceivably be exploited for remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://sourceforge.net/p/isync/isync/commit_browser https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=999804 https://sourceforge.net/p/isync/isync/ref/master/tags/ http://www.openwall.com/lists/oss-security/2021/12/03/2 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CYZ2GNB4ZO2T27D2XNUWMCS3THZYSJQU/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCBSY7OZ57XNC6ZYXF6WU5KBSWITZVDX/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: