CVE-2021-3578
7.8HIGHA flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated struc
Publicado: 2/16/2022Atualizado: 11/21/2024
Descrição
A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.
Análise IADesenvolvido por IA
Produtos Afetados
isync_projectisync
isync_projectisync
1.4.0
isync_projectisync
1.4.1
fedoraprojectfedora
33
fedoraprojectfedora
34
debiandebian_linux
9.0
Referências
- http://www.openwall.com/lists/oss-security/2021/06/07/1Mailing ListPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1961710Not Applicable
- https://bugzilla.redhat.com/show_bug.cgi?id=1967397Issue TrackingPatchThird Party Advisory
- https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/Not Applicable
- https://lists.debian.org/debian-lts-announce/2022/07/msg00001.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPIDLIJKNRJHUVBCL7QGAPAAVPIHQGXK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U75UFEWRAZYKVL5NHMPBUOLWN3WXTOEI/
- https://security.gentoo.org/glsa/202208-15Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/06/07/1Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/06/07/1Mailing ListPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1961710Not Applicable
- https://bugzilla.redhat.com/show_bug.cgi?id=1967397Issue TrackingPatchThird Party Advisory
- https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/Not Applicable
- https://lists.debian.org/debian-lts-announce/2022/07/msg00001.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPIDLIJKNRJHUVBCL7QGAPAAVPIHQGXK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U75UFEWRAZYKVL5NHMPBUOLWN3WXTOEI/
- https://security.gentoo.org/glsa/202208-15Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/06/07/1Mailing ListPatchThird Party Advisory