Bug 1185705 - (CVE-2021-32055) VUL-0: CVE-2021-32055: mutt,neomutt: Out of bounds read in IMAP parser
(CVE-2021-32055)
VUL-0: CVE-2021-32055: mutt,neomutt: Out of bounds read in IMAP parser
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: David Sterba
Security Team bot
https://smash.suse.de/issue/283520/
CVSSv3.1:SUSE:CVE-2021-32055:5.3:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-05-06 09:12 UTC by Robert Frohl
Modified: 2022-06-21 16:16 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Dr. Werner Fink 2021-05-07 07:18:02 UTC
SLE-15 does only have mutt-1.10.1
SLE-12 does only have mutt-1.10.1
Hence only Factory/Tumbleweed is affected and this should be solved with update to mutt 2.0.7
Comment 2 Dr. Werner Fink 2021-05-07 07:23:55 UTC
(In reply to Dr. Werner Fink from comment #1)
> SLE-15 does only have mutt-1.10.1
> SLE-12 does only have mutt-1.10.1
> Hence only Factory/Tumbleweed is affected and this should be solved with
> update to mutt 2.0.7

Patch does not find the function not fitting code, that it seems really apply only for mutt-1.11.0 and above
Comment 3 OBSbugzilla Bot 2021-05-07 08:00:03 UTC
This is an autogenerated message for OBS integration:
This bug (1185705) was mentioned in
https://build.opensuse.org/request/show/891208 Factory / mutt
Comment 4 Dr. Werner Fink 2021-05-07 15:13:30 UTC
Next is neomutt
Comment 5 Robert Frohl 2021-07-14 08:28:45 UTC
(In reply to Dr. Werner Fink from comment #2)
> (In reply to Dr. Werner Fink from comment #1)
> > SLE-15 does only have mutt-1.10.1
> > SLE-12 does only have mutt-1.10.1
> > Hence only Factory/Tumbleweed is affected and this should be solved with
> > update to mutt 2.0.7
> 
> Patch does not find the function not fitting code, that it seems really
> apply only for mutt-1.11.0 and above

sorry for the late reply.

I will update my incorrect tracking and close.
Comment 6 Robert Frohl 2021-07-14 08:30:43 UTC
(In reply to Dr. Werner Fink from comment #4)
> Next is neomutt

seems to be missing for neomutt, will leave the bug open for now.
Comment 7 OBSbugzilla Bot 2022-06-14 18:40:04 UTC
This is an autogenerated message for OBS integration:
This bug (1185705) was mentioned in
https://build.opensuse.org/request/show/982645 Backports:SLE-15-SP4 / neomutt
Comment 8 Swamp Workflow Management 2022-06-21 16:16:37 UTC
openSUSE-SU-2022:10020-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1184787,1185705
CVE References: CVE-2021-32055,CVE-2022-1328
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    neomutt-20220429-bp154.2.3.1