rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "rfc822.c" }, "deprecated": false, "digest": { "line_hashes": [ "119922534699700865141855793049624050921", "332665935867995423402956330231494240991", "113335306993783950353079467662358066062", "56054890969183425964261008809715413083", "15821560693194673009670366725139481041", "147877264450199877172028045231315787752", "264553291052471526685305788884150907624", "155537299934522521569547473095866518833", "77949292764677261573303057440465213463", "6999739727252690263416602034441293005", "144951443424373747271981120756631784773", "322127592728552953921177602651402808684", "260875731909127696761130908418911405081", "180830938022783171785510199746013939504", "24243105577259289922807719596320141540", "62462404231016380828020626158156355570" ], "threshold": 0.9 }, "id": "CVE-2021-3181-434d395c", "source": "https://gitlab.com/muttmua/mutt@939b02b33ae29bc0d642570c1dcfd4b339037d19" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "rfc822.c", "function": "rfc822_parse_adrlist" }, "deprecated": false, "digest": { "length": 3586.0, "function_hash": "126037132878735577070376896834556723105" }, "id": "CVE-2021-3181-75e8e631", "source": "https://gitlab.com/muttmua/mutt@939b02b33ae29bc0d642570c1dcfd4b339037d19" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "rfc822.c", "function": "rfc822_parse_adrlist" }, "deprecated": false, "digest": { "length": 3590.0, "function_hash": "263707038947612484698445817127090691131" }, "id": "CVE-2021-3181-86ac11dc", "source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "rfc822.c" }, "deprecated": false, "digest": { "line_hashes": [ "44064037161136642093186503649177487535", "190402456001848709447198538528851128836", "115329182337499589335103687504581291960", "311493693951459938537062791570122325124", "58539714682203662620009591366323991427", "104096131218460858900122216256241288988", "121882502105934751420308939305441686657", "207321429528723917740934594736984658584" ], "threshold": 0.9 }, "id": "CVE-2021-3181-e691b2b7", "source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17" } ] }