PT-2004-1132 · Cyrus · Cyrus Imap Server
Published
2004-05-20
·
Updated
2017-07-11
·
CVE-2002-1580
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cyrus IMAP server versions 1.4 and 2.1.10
Description
The issue is related to an integer overflow in the imapparse.c file, which can be exploited by remote attackers to execute arbitrary code. This is achieved by providing a large length value that facilitates a buffer overflow attack.
Recommendations
For Cyrus IMAP server version 1.4, update to a version that fixes the integer overflow issue in imapparse.c.
For Cyrus IMAP server version 2.1.10, update to a version that fixes the integer overflow issue in imapparse.c.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cyrus Imap Server