PT-2004-1132 · Cyrus · Cyrus Imap Server

Published

2004-05-20

·

Updated

2017-07-11

·

CVE-2002-1580

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cyrus IMAP server versions 1.4 and 2.1.10
Description The issue is related to an integer overflow in the imapparse.c file, which can be exploited by remote attackers to execute arbitrary code. This is achieved by providing a large length value that facilitates a buffer overflow attack.
Recommendations For Cyrus IMAP server version 1.4, update to a version that fixes the integer overflow issue in imapparse.c. For Cyrus IMAP server version 2.1.10, update to a version that fixes the integer overflow issue in imapparse.c. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1580
DSA-215

Affected Products

Cyrus Imap Server