Arch Linux Security Advisory ASA-202102-38
=========================================
Severity: High
Date    : 2021-02-27
CVE-ID  : CVE-2021-20247
Package : isync
Type    : directory traversal
Remote  : Yes
Link    : https://security.archlinux.org/AVG-1598

Summary
======
The package isync before version 1.3.5-1 is vulnerable to directory
traversal.

Resolution
=========
Upgrade to 1.3.5-1.

# pacman -Syu "isync>=1.3.5-1"

The problem has been fixed upstream in version 1.3.5.

Workaround
=========
None.

Description
==========
A security issue was found in isync/mbsync before versions 1.3.5 and
1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do
not occur, allowing a malicious or compromised server to use specially
crafted mailbox names containing '..' path components to access data
outside the designated mailbox on the opposite end of the
synchronization channel.

Impact
=====
A compromised server could traverse files on the system.

References
=========
https://www.openwall.com/lists/oss-security/2021/02/22/1
https://sourceforge.net/p/isync/isync/ci/fe5d59f8e3169944e57eb1c60155c9ebd4912d48/
https://security.archlinux.org/CVE-2021-20247

ArchLinux: 202102-38: isync: directory traversal

March 1, 2021

Summary

A security issue was found in isync/mbsync before versions 1.3.5 and 1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur, allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel.

Resolution

Upgrade to 1.3.5-1. # pacman -Syu "isync>=1.3.5-1"
The problem has been fixed upstream in version 1.3.5.

References

https://www.openwall.com/lists/oss-security/2021/02/22/1 https://sourceforge.net/p/isync/isync/ci/fe5d59f8e3169944e57eb1c60155c9ebd4912d48/ https://security.archlinux.org/CVE-2021-20247

Severity
Package : isync
Type : directory traversal
Remote : Yes
Link : https://security.archlinux.org/AVG-1598

Workaround

None.

Related News