PT-2019-2928 · Cyrus+4 · Cyrus Imap+4

Published

2019-06-03

·

Updated

2025-04-04

·

CVE-2019-11356

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cyrus IMAP versions 2.5.x through 2.5.12 Cyrus IMAP versions 3.0.x through 3.0.9
Description The issue is related to the CalDAV feature in the httpd server of Cyrus IMAP, which allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. This can lead to data integrity issues, access to confidential data, denial of service, and arbitrary code execution.
Recommendations For versions 2.5.x through 2.5.12, consider disabling the CalDAV feature until a patch is available. For versions 3.0.x through 3.0.9, restrict access to the HTTP PUT operation for events with long iCalendar property names to minimize the risk of exploitation. As a temporary workaround, consider disabling the httpd server or restricting its functionality until a patch is available.

Fix

RCE

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2469
ALT-PU-2019-2472
BDU:2019-02901
CESA-2019_1771
CVE-2019-11356
DSA-4458-1
MGASA-2019-0219
OPENSUSE-SU-2025:14968-1
RHSA-2019:1771
RHSA-2019_1771
USN-4566-1

Affected Products

Alt Linux
Centos
Cyrus Imap
Red Hat
Ubuntu