CVE-2021-3181

Description

rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.997

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2021:0196-1(SUSE Linux Enterprise Server 12-SP5 ) mutt-1.10.1-55.24.1.x86_64.rpmLinux
SUSE-SU-2021:0196-1(SUSE Linux Enterprise Server 12-SP5 ) mutt-debuginfo-1.10.1-55.24.1.x86_64.rpmLinux
SUSE-SU-2021:0196-1(SUSE Linux Enterprise Server 12-SP5 ) mutt-debugsource-1.10.1-55.24.1.x86_64.rpmLinux
mutt security update(DSA-4838-1) mutt_1.10.1-2.1+deb10u5_i386.debLinux
mutt security update(DSA-4838-1) mutt_1.10.1-2.1+deb10u5_amd64.debLinux
text-based mailreader supporting MIME, GPG, PGP and threading (USN-4703-1) mutt_1.9.4-3ubuntu0.5_i386.debLinux
text-based mailreader supporting MIME, GPG, PGP and threading (USN-4703-1) mutt_1.9.4-3ubuntu0.5_amd64.debLinux
text-based mailreader supporting MIME, GPG, PGP and threading (USN-4703-1) mutt_1.13.2-1ubuntu0.4_amd64.debLinux
text-based mailreader supporting MIME, GPG, PGP and threading (USN-4703-1) mutt_1.14.6-1ubuntu0.2_amd64.debLinux
text-based mailreader supporting MIME, GPG, PGP and threading (USN-4703-1) mutt_1.5.24-1ubuntu0.6_i386.debLinux
text-based mailreader supporting MIME, GPG, PGP and threading (USN-4703-1) mutt_1.5.24-1ubuntu0.6_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234