Search CVE reports
1 – 10 of 11 results
Some fixes available 2 of 5
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | Not affected | Fixed | Fixed | Ignored | Ignored |
| cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | — |
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | Not affected | Not affected | Not affected | Fixed | Fixed |
| cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | — | — | — | — | Not affected |
| cyrus-imapd-2.4 | — | — | — | — | Not in release |
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | Not affected | Not affected | Not affected | Not affected | Not affected |
| cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. ...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | Not affected | Not affected | Not affected | Not affected | Not affected |
| cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via...
1 affected package
cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.4 | — | — | — | — | Not in release |
Some fixes available 2 of 15
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
3 affected packages
cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.2 | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
| kolab-cyrus-imapd | — | — | — | — | — |
Some fixes available 2 of 18
The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via...
3 affected packages
cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.2 | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
| kolab-cyrus-imapd | — | — | — | — | — |
Some fixes available 2 of 15
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.
3 affected packages
cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.2 | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
| kolab-cyrus-imapd | — | — | — | — | — |