← Zuruck zu CVEs
CVE-2021-3181
MEDIUM6.5
Beschreibung
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht1/19/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
debian:debian_linuxfedoraproject:fedoramutt:mutt
Schwachen (CWE)
CWE-401
Referenzen
http://www.openwall.com/lists/oss-security/2021/01/19/10(cve@mitre.org)
http://www.openwall.com/lists/oss-security/2021/01/27/3(cve@mitre.org)
https://gitlab.com/muttmua/mutt/-/issues/323(cve@mitre.org)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXGWXFO77HBCD3VYEIYHHYU33LYWWWNQ/(cve@mitre.org)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2OMLQKAOHPYQA4GI7ZUO6UKCPUHLYO7/(cve@mitre.org)
https://security.gentoo.org/glsa/202101-25(cve@mitre.org)
https://www.debian.org/security/2021/dsa-4838(cve@mitre.org)
http://www.openwall.com/lists/oss-security/2021/01/19/10(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2021/01/27/3(af854a3a-2127-422b-91ae-364da2661108)
https://gitlab.com/muttmua/mutt/-/commit/4a2becbdb4422aaffe3ce314991b9d670b7adf17(af854a3a-2127-422b-91ae-364da2661108)
https://gitlab.com/muttmua/mutt/-/commit/939b02b33ae29bc0d642570c1dcfd4b339037d19(af854a3a-2127-422b-91ae-364da2661108)
https://gitlab.com/muttmua/mutt/-/commit/d4305208955c5cdd9fe96dfa61e7c1e14e176a14(af854a3a-2127-422b-91ae-364da2661108)
https://gitlab.com/muttmua/mutt/-/issues/323(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2021/01/msg00017.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXGWXFO77HBCD3VYEIYHHYU33LYWWWNQ/(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2OMLQKAOHPYQA4GI7ZUO6UKCPUHLYO7/(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202101-25(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2021/dsa-4838(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.