rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"119922534699700865141855793049624050921",
"332665935867995423402956330231494240991",
"113335306993783950353079467662358066062",
"56054890969183425964261008809715413083",
"15821560693194673009670366725139481041",
"147877264450199877172028045231315787752",
"264553291052471526685305788884150907624",
"155537299934522521569547473095866518833",
"77949292764677261573303057440465213463",
"6999739727252690263416602034441293005",
"144951443424373747271981120756631784773",
"322127592728552953921177602651402808684",
"260875731909127696761130908418911405081",
"180830938022783171785510199746013939504",
"24243105577259289922807719596320141540",
"62462404231016380828020626158156355570"
]
},
"id": "CVE-2021-3181-434d395c",
"source": "https://gitlab.com/muttmua/mutt@939b02b33ae29bc0d642570c1dcfd4b339037d19",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "rfc822.c"
},
"signature_type": "Line"
},
{
"digest": {
"function_hash": "126037132878735577070376896834556723105",
"length": 3586.0
},
"id": "CVE-2021-3181-75e8e631",
"source": "https://gitlab.com/muttmua/mutt@939b02b33ae29bc0d642570c1dcfd4b339037d19",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "rfc822_parse_adrlist",
"file": "rfc822.c"
},
"signature_type": "Function"
},
{
"digest": {
"function_hash": "263707038947612484698445817127090691131",
"length": 3590.0
},
"id": "CVE-2021-3181-86ac11dc",
"source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "rfc822_parse_adrlist",
"file": "rfc822.c"
},
"signature_type": "Function"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"44064037161136642093186503649177487535",
"190402456001848709447198538528851128836",
"115329182337499589335103687504581291960",
"311493693951459938537062791570122325124",
"58539714682203662620009591366323991427",
"104096131218460858900122216256241288988",
"121882502105934751420308939305441686657",
"207321429528723917740934594736984658584"
]
},
"id": "CVE-2021-3181-e691b2b7",
"source": "https://gitlab.com/muttmua/mutt@4a2becbdb4422aaffe3ce314991b9d670b7adf17",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "rfc822.c"
},
"signature_type": "Line"
}
]