VDB

CVE-2021-32055

CVE-2021-32055 PUBLISHED

Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.

EPSS 0.37% · 58.9th percentile

Risk Scores

EPSS Score
0.37%
58.9th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmutt1.13.2-1ubuntu0.1, 1.13.2-1ubuntu0.4, 1.13.2-1ubuntu0.3
Ubuntu:Pro:16.04:LTSmutt1.5.23-3.1ubuntu1, 1.5.24-1ubuntu0.3, 1.5.24-1ubuntu0.4
Ubuntu:Pro:20.04:LTSneomutt*, 0, 20191207+dfsg.1-1.1

Timeline

  • May 5, 2021 CVE Published
  • May 6, 2021 EPSS Score
  • Jul 9, 2021 EPSS Score
  • Sep 9, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 11, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 13, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
  • Sep 16, 2022 EPSS Score
  • Nov 17, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›