Hide Forgot
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution. Reference: https://www.openwall.com/lists/oss-security/2021/12/03/1
Created isync tracking bugs for this issue: Affects: epel-all [bug 2028934] Affects: fedora-all [bug 2028933]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.