CVE-2021-3181

Name
CVE-2021-3181
Description
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://gitlab.com/muttmua/mutt/-/commit/4a2becbdb4422aaffe3ce314991b9d670b7adf17
Third Party Advisory https://gitlab.com/muttmua/mutt/-/issues/323
Patch https://gitlab.com/muttmua/mutt/-/commit/939b02b33ae29bc0d642570c1dcfd4b339037d19
Patch https://gitlab.com/muttmua/mutt/-/commit/d4305208955c5cdd9fe96dfa61e7c1e14e176a14
Mailing List http://www.openwall.com/lists/oss-security/2021/01/19/10
Third Party Advisory https://www.debian.org/security/2021/dsa-4838
Mailing List https://lists.debian.org/debian-lts-announce/2021/01/msg00017.html
Third Party Advisory https://security.gentoo.org/glsa/202101-25
Mailing List http://www.openwall.com/lists/oss-security/2021/01/27/3
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DXGWXFO77HBCD3VYEIYHHYU33LYWWWNQ/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2OMLQKAOHPYQA4GI7ZUO6UKCPUHLYO7/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mutt:mutt:*:*:*:*:*:*:*:* mutt >= None <= 2.0.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status