Cyrus IMAP 3.0.0 Release Candidate 3

CPE Details

Cyrus IMAP 3.0.0 Release Candidate 3
3.0.0
2019-06-04
14h07 +00:00
2019-06-04
14h07 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:cyrus:imap:3.0.0:rc3:*:*:*:*:*:*

Informations

Vendor

cyrus

Product

imap

Version

3.0.0

Update

rc3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-33582 2021-09-01 03h32 +00:00 Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
7.5
Haute
CVE-2021-32056 2021-05-10 11h05 +00:00 Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
4.3
Moyen
CVE-2019-19783 2019-12-16 12h06 +00:00 An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.
6.5
Moyen
CVE-2019-18928 2019-11-15 02h45 +00:00 Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
9.8
Critique
CVE-2019-11356 2019-06-03 17h44 +00:00 The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
9.8
Critique
CVE-2017-14230 2017-09-10 07h00 +00:00 In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
9.1
Critique