CVE-2021-32055
—CVSS 3.1
9.1 critical
EPSS
3%p84
Published
()
Modified
Description
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.
In the news0 stories
No ingested article mentions this CVE yet.