PT-2019-2928 · Cyrus+4 · Cyrus Imap+4
Published
2019-06-03
·
Updated
2025-04-04
·
CVE-2019-11356
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cyrus IMAP versions 2.5.x through 2.5.12
Cyrus IMAP versions 3.0.x through 3.0.9
Description
The issue is related to the CalDAV feature in the httpd server of Cyrus IMAP, which allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. This can lead to data integrity issues, access to confidential data, denial of service, and arbitrary code execution.
Recommendations
For versions 2.5.x through 2.5.12, consider disabling the CalDAV feature until a patch is available.
For versions 3.0.x through 3.0.9, restrict access to the HTTP PUT operation for events with long iCalendar property names to minimize the risk of exploitation.
As a temporary workaround, consider disabling the
httpd server or restricting its functionality until a patch is available.Fix
RCE
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Cyrus Imap
Red Hat
Ubuntu