Bug 2144914 (CVE-2022-4121) - CVE-2022-4121 libetpan: Null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c
Summary: CVE-2022-4121 libetpan: Null pointer dereference in mailimap_mailbox_data_sta...
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2022-4121
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2144915
Blocks: 2144916
TreeView+ depends on / blocked
 
Reported: 2022-11-22 18:11 UTC by Pedro Sampaio
Modified: 2022-12-07 22:18 UTC (History)
0 users

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-12-07 22:18:02 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2022-11-22 18:11:25 UTC
A segmentation fault due to a null pointer dereference has been found in the IMAP STATUS command handling component. The error occurs when mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c when it tries to free st_info_list of mb_data_status. The segmentation fault is triggered when an invalid STATUS response is received. This can at least lead to a Denial Of Service.

Upstream issue:

https://github.com/dinhvh/libetpan/issues/420

Comment 1 Pedro Sampaio 2022-11-22 18:11:41 UTC
Created libetpan tracking bugs for this issue:

Affects: fedora-all [bug 2144915]

Comment 2 Product Security DevOps Team 2022-12-07 22:18:00 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.