7.2
CVSSv2

CVE-2021-3578

Published: 16/02/2022 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isync project isync 1.4.1

isync project isync 1.4.0

isync project isync

fedoraproject fedora 33

fedoraproject fedora 34

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #989564 isync: CVE-2021-3578 Package: src:isync; Maintainer for src:isync is Nicolas Boullis <nboullis@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 7 Jun 2021 16:09:02 UTC Severity: grave Tags: security, upstream Found in versions isync/130-21, isync/13 ...
A security issue was found in mbsync before version 142, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response This could be plausibly exploited for remote code execution on the client ...