Resource exhaustion in Mutt - CVE-2021-3181
Published: January 19, 2021 / Updated: January 26, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when handling email messages with sequences of semicolon characters in RFC822 address fields. A remote attacker can send a specially crafted email message, force the application to consume a huge amount of memory and perform a denial of service (DoS) attack.
Affected software
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
mutt (Debian package)
mutt (Alpine package)
mutt (Ubuntu package)
mutt
mutt-debuginfo
mutt-debugsource
mutt-help
mutt (Red Hat package)
How to mitigate CVE-2021-3181
mutt (Debian package) - update to 1.10.1-2.1+deb10u5
mutt (Alpine package) - update to 1.14.7-r0
mutt (Ubuntu package) - addressed in versions 1.5.24-1ubuntu0.6, 1.9.4-3ubuntu0.5, 1.13.2-1ubuntu0.4, 1.14.6-1ubuntu0.2
mutt - update to 1.10.1-4
mutt-debuginfo - update to 1.10.1-4
mutt-debugsource - update to 1.10.1-4
mutt-help - update to 1.10.1-4
mutt - addressed in versions 2.0.5-1.fc32, 2.0.5-1.fc33
mutt (Red Hat package) - update to 2.0.7-1.el8
External References
- http://www.openwall.com/lists/oss-security/2021/01/19/10
- https://gitlab.com/muttmua/mutt/-/commit/4a2becbdb4422aaffe3ce314991b9d670b7adf17
- https://gitlab.com/muttmua/mutt/-/commit/939b02b33ae29bc0d642570c1dcfd4b339037d19
- https://gitlab.com/muttmua/mutt/-/commit/d4305208955c5cdd9fe96dfa61e7c1e14e176a14
- https://gitlab.com/muttmua/mutt/-/issues/323