rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.
[
{
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@d4305208955c5cdd9fe96dfa61e7c1e14e176a14",
"id": "CVE-2021-3181-6da71b13",
"target": {
"file": "rfc822.c",
"function": "rfc822_parse_adrlist"
},
"digest": {
"function_hash": "50134787346260602477409367282502923963",
"length": 3623.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17",
"id": "CVE-2021-3181-86ac11dc",
"target": {
"file": "rfc822.c",
"function": "rfc822_parse_adrlist"
},
"digest": {
"function_hash": "263707038947612484698445817127090691131",
"length": 3590.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17",
"id": "CVE-2021-3181-e691b2b7",
"target": {
"file": "rfc822.c"
},
"digest": {
"line_hashes": [
"44064037161136642093186503649177487535",
"190402456001848709447198538528851128836",
"115329182337499589335103687504581291960",
"311493693951459938537062791570122325124",
"58539714682203662620009591366323991427",
"104096131218460858900122216256241288988",
"121882502105934751420308939305441686657",
"207321429528723917740934594736984658584"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3181.json"