CVE-2021-3181

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3181
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3181.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3181
Downstream
Related
Published
2021-01-19T15:15:12Z
Modified
2025-10-14T18:23:53.532331Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.

References

Affected packages

Git / gitlab.com/muttmua/mutt

Affected ranges

Type
GIT
Repo
https://gitlab.com/muttmua/mutt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Type
GIT
Repo
https://github.com/muttmua/mutt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected

Affected versions

Other

mutt-0-92-10i
mutt-0-92-11i
mutt-0-92-9i
mutt-0-93-unstable
mutt-0-94-10i-rel
mutt-0-94-13-rel
mutt-0-94-14-rel
mutt-0-94-15-rel
mutt-0-94-16i-rel
mutt-0-94-17i-rel
mutt-0-94-18-rel
mutt-0-94-5i-rel
mutt-0-94-6i-rel
mutt-0-94-7i-rel
mutt-0-94-8i-rel
mutt-0-94-9i-p1
mutt-0-94-9i-rel
mutt-0-95-rel
mutt-0-96-1-rel
mutt-0-96-2-slightly-post-release
mutt-0-96-3-rel
mutt-0-96-4-rel
mutt-0-96-5-rel
mutt-0-96-6-rel
mutt-0-96-7-rel
mutt-0-96-8-rel
mutt-0-96-rel
mutt-1-1-1-1-rel
mutt-1-1-1-2-rel
mutt-1-1-1-rel
mutt-1-1-10-rel
mutt-1-1-11-rel
mutt-1-1-12-rel
mutt-1-1-13-rel
mutt-1-1-14-rel
mutt-1-1-2-rel
mutt-1-1-3-rel
mutt-1-1-4-rel
mutt-1-1-5-rel
mutt-1-1-6-rel
mutt-1-1-7-rel
mutt-1-1-8-rel
mutt-1-1-9-rel
mutt-1-1-rel
mutt-1-10-1-rel
mutt-1-10-rel
mutt-1-11-1-rel
mutt-1-11-2-rel
mutt-1-11-3-rel
mutt-1-11-4-rel
mutt-1-11-rel
mutt-1-12-1-rel
mutt-1-12-2-rel
mutt-1-12-rel
mutt-1-13-1-rel
mutt-1-13-2-rel
mutt-1-13-3-rel
mutt-1-13-4-rel
mutt-1-13-5-rel
mutt-1-13-rel
mutt-1-14-1-rel
mutt-1-14-2-rel
mutt-1-14-3-rel
mutt-1-14-4-rel
mutt-1-14-5-rel
mutt-1-14-6-rel
mutt-1-14-7-rel
mutt-1-14-rel
mutt-1-3-1-rel
mutt-1-3-10-rel
mutt-1-3-11-rel
mutt-1-3-12-rel
mutt-1-3-13-rel
mutt-1-3-14-rel
mutt-1-3-15-rel
mutt-1-3-16-rel
mutt-1-3-17-rel
mutt-1-3-18-rel
mutt-1-3-19-rel
mutt-1-3-2-rel
mutt-1-3-20-rel
mutt-1-3-21-rel
mutt-1-3-22-1-rel
mutt-1-3-22-rel
mutt-1-3-23-1-rel
mutt-1-3-23-2-rel
mutt-1-3-23-rel
mutt-1-3-24-rel
mutt-1-3-25-rel
mutt-1-3-26-rel
mutt-1-3-27-rel
mutt-1-3-3-rel
mutt-1-3-4-rel
mutt-1-3-5-rel
mutt-1-3-6-rel
mutt-1-3-7-rel
mutt-1-3-8-rel
mutt-1-3-9-rel
mutt-1-3-rel
mutt-1-5-1-rel
mutt-1-5-10-rel
mutt-1-5-11-rel
mutt-1-5-12-rel
mutt-1-5-13-rel
mutt-1-5-14-rel
mutt-1-5-15-rel
mutt-1-5-16-rel
mutt-1-5-17-rel
mutt-1-5-18-rel
mutt-1-5-19-rel
mutt-1-5-2-rel
mutt-1-5-20-rel
mutt-1-5-21-rel
mutt-1-5-22-rel
mutt-1-5-23-rel
mutt-1-5-24-rel
mutt-1-5-3-rel
mutt-1-5-4-rel
mutt-1-5-5-1-rel
mutt-1-5-5-rel
mutt-1-5-6-rel
mutt-1-5-7-rel
mutt-1-5-8-rel
mutt-1-5-9-rel
mutt-1-6-1-rel
mutt-1-6-2-rel
mutt-1-6-rel
mutt-1-7-1-rel
mutt-1-7-2-rel
mutt-1-7-rel
mutt-1-8-1-rel
mutt-1-8-2-rel
mutt-1-8-3-rel
mutt-1-8-rel
mutt-1-9-1-rel
mutt-1-9-2-rel
mutt-1-9-3-rel
mutt-1-9-4-rel
mutt-1-9-5-rel
mutt-1-9-rel
mutt-2-0-1-rel
mutt-2-0-2-rel
mutt-2-0-3-rel
mutt-2-0-4-rel
mutt-2-0-rel
post-type-punning-patch
pre-type-punning-patch

Database specific

{
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "signature_type": "Line",
            "target": {
                "file": "rfc822.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "119922534699700865141855793049624050921",
                    "332665935867995423402956330231494240991",
                    "113335306993783950353079467662358066062",
                    "56054890969183425964261008809715413083",
                    "15821560693194673009670366725139481041",
                    "147877264450199877172028045231315787752",
                    "264553291052471526685305788884150907624",
                    "155537299934522521569547473095866518833",
                    "77949292764677261573303057440465213463",
                    "6999739727252690263416602034441293005",
                    "144951443424373747271981120756631784773",
                    "322127592728552953921177602651402808684",
                    "260875731909127696761130908418911405081",
                    "180830938022783171785510199746013939504",
                    "24243105577259289922807719596320141540",
                    "62462404231016380828020626158156355570"
                ],
                "threshold": 0.9
            },
            "id": "CVE-2021-3181-434d395c",
            "source": "https://gitlab.com/muttmua/mutt@939b02b33ae29bc0d642570c1dcfd4b339037d19"
        },
        {
            "signature_version": "v1",
            "signature_type": "Function",
            "target": {
                "file": "rfc822.c",
                "function": "rfc822_parse_adrlist"
            },
            "deprecated": false,
            "digest": {
                "length": 3586.0,
                "function_hash": "126037132878735577070376896834556723105"
            },
            "id": "CVE-2021-3181-75e8e631",
            "source": "https://gitlab.com/muttmua/mutt@939b02b33ae29bc0d642570c1dcfd4b339037d19"
        },
        {
            "signature_version": "v1",
            "signature_type": "Function",
            "target": {
                "file": "rfc822.c",
                "function": "rfc822_parse_adrlist"
            },
            "deprecated": false,
            "digest": {
                "length": 3590.0,
                "function_hash": "263707038947612484698445817127090691131"
            },
            "id": "CVE-2021-3181-86ac11dc",
            "source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17"
        },
        {
            "signature_version": "v1",
            "signature_type": "Line",
            "target": {
                "file": "rfc822.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "44064037161136642093186503649177487535",
                    "190402456001848709447198538528851128836",
                    "115329182337499589335103687504581291960",
                    "311493693951459938537062791570122325124",
                    "58539714682203662620009591366323991427",
                    "104096131218460858900122216256241288988",
                    "121882502105934751420308939305441686657",
                    "207321429528723917740934594736984658584"
                ],
                "threshold": 0.9
            },
            "id": "CVE-2021-3181-e691b2b7",
            "source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17"
        }
    ]
}