Resource exhaustion in Mutt - CVE-2021-3181

 

Resource exhaustion in Mutt - CVE-2021-3181

Published: January 19, 2021 / Updated: January 26, 2021


Vulnerability identifier: #VU50017
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3181
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation when handling email messages with sequences of semicolon characters in RFC822 address fields. A remote attacker can send a specially crafted email message, force the application to consume a huge amount of memory and perform a denial of service (DoS) attack.


Affected software

Mutt
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
mutt (Debian package)
mutt (Alpine package)
mutt (Ubuntu package)
mutt
mutt-debuginfo
mutt-debugsource
mutt-help
mutt (Red Hat package)

How to mitigate CVE-2021-3181

Install updates from vendor's website.

Mutt - update to 2.0.5
mutt (Debian package) - update to 1.10.1-2.1+deb10u5
mutt (Alpine package) - update to 1.14.7-r0
mutt (Ubuntu package) - addressed in versions 1.5.24-1ubuntu0.6, 1.9.4-3ubuntu0.5, 1.13.2-1ubuntu0.4, 1.14.6-1ubuntu0.2
mutt - update to 1.10.1-4
mutt-debuginfo - update to 1.10.1-4
mutt-debugsource - update to 1.10.1-4
mutt-help - update to 1.10.1-4
mutt - addressed in versions 2.0.5-1.fc32, 2.0.5-1.fc33
mutt (Red Hat package) - update to 2.0.7-1.el8

External References

Related Security Bulletins