CVE-2021-3578

7.8HIGH

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated struc

게시됨: 2/16/2022업데이트됨: 11/21/2024

설명

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

AI 분석AI 기반

영향받는 제품

isync_projectisync
isync_projectisync
1.4.0
isync_projectisync
1.4.1
fedoraprojectfedora
33
fedoraprojectfedora
34
debiandebian_linux
9.0

참조