UBUNTU-CVE-2021-32055
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-32055
UBUNTU-CVE-2021-32055
Summary:
Details: Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.
References: https://ubuntu.com/security/CVE-2021-32055, https://github.com/neomutt/neomutt/releases/tag/20211015, http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20210503/000036.html, https://ubuntu.com/security/notices/USN-5392-1, https://www.cve.org/CVERecord?id=CVE-2021-32055, https://ubuntu.com/security/notices/USN-7204-1
Affected packages
Package
Name: mutt
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
