PT-2019-2928 · Cyrus+4 · Cyrus Imap+4

Publicado

2019-06-03

·

Atualizado

2025-04-04

·

CVE-2019-11356

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cyrus IMAP versions 2.5.x through 2.5.12 Cyrus IMAP versions 3.0.x through 3.0.9
Description The issue is related to the CalDAV feature in the httpd server of Cyrus IMAP, which allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. This can lead to data integrity issues, access to confidential data, denial of service, and arbitrary code execution.
Recommendations For versions 2.5.x through 2.5.12, consider disabling the CalDAV feature until a patch is available. For versions 3.0.x through 3.0.9, restrict access to the HTTP PUT operation for events with long iCalendar property names to minimize the risk of exploitation. As a temporary workaround, consider disabling the httpd server or restricting its functionality until a patch is available.

Correção

RCE

Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2469
ALT-PU-2019-2472
BDU:2019-02901
CESA-2019_1771
CVE-2019-11356
DSA-4458-1
MGASA-2019-0219
OPENSUSE-SU-2025:14968-1
RHSA-2019:1771
RHSA-2019_1771
USN-4566-1

Produtos afetados

Alt Linux
Centos
Cyrus Imap
Red Hat
Ubuntu