PT-2019-5233 · Cyrus+4 · Cyrus Imap+4

Published

2019-12-16

·

Updated

2025-04-04

·

CVE-2019-19783

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cyrus IMAP versions prior to 2.5.15 Cyrus IMAP versions 3.0.x prior to 3.0.13 Cyrus IMAP versions 3.1.x through 3.1.8
Description The issue is related to a lack of input validation mechanism in the Cyrus IMAP server, which can be exploited by a remote attacker to impact the integrity of information. If sieve script uploading is allowed or certain non-default sieve options are enabled, a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges due to folder mishandling in the autosieve createfolder() function.
Recommendations For Cyrus IMAP versions prior to 2.5.15, update to version 2.5.15 or later. For Cyrus IMAP versions 3.0.x prior to 3.0.13, update to version 3.0.13 or later. For Cyrus IMAP versions 3.1.x through 3.1.8, update to a version later than 3.1.8. As a temporary workaround, consider disabling sieve script uploading or restricting the use of non-default sieve options until a patch is available.

Fix

Improper Privilege Management

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1001
ALT-PU-2020-1020
BDU:2020-01976
CESA-2020_4655
CVE-2019-19783
DSA-4590-1
MGASA-2020-0010
OPENSUSE-SU-2025:14968-1
RHSA-2020:4655
RHSA-2020_4655
USN-4566-1

Affected Products

Alt Linux
Centos
Cyrus Imap
Red Hat
Ubuntu