CVE-2021-3657 is a critical buffer overflow vulnerability affecting mbsync versions prior to 1.4.4, impacting Debian, Fedora, isync_project, and Red Hat distributions. Malicious or compromised IMAP servers, or even external email senders, could trigger this flaw by sending extremely large IMAP literals (>=2GiB). This could lead to remote code execution due to multiple buffer overflows. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk with a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. It does not require user interaction or privileges. Despite its critical severity, there is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.4CPE matchmatch criteria | cpe:2.3:a:isync_project:isync:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.