Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.
2021-05-05T16:15:08.117
2024-11-21T06:06:46.627
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:M/Au:N/C:P/I:N/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mutt | mutt | < 2.0.7 | Yes |
Application | neomutt | neomutt | ≤ 20210504 | Yes |