Debian Security Advisory

DLA-3066-1 isync -- LTS security update

Date Reported:
01 Jul 2022
Affected Packages:
isync
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 983351, Bug 989564.
In Mitre's CVE dictionary: CVE-2021-3578, CVE-2021-3657, CVE-2021-20247.
More information:

Several security vulnerabilities have been discovered in isync, an IMAP and MailDir mailbox synchronizer. An malicious attacker who can control an IMAP server may exploit these flaws for remote code execution.

For Debian 9 stretch, these problems have been fixed in version 1.2.1-2+deb9u1.

We recommend that you upgrade your isync packages.

For the detailed security status of isync please refer to its security tracker page at: https://security-tracker.debian.org/tracker/isync

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS