PT-2024-4038 · Unknown+7 · Cyrus Imap+7

·

CVE-2024-34055

·

Published

2024-06-05

·

Updated

2025-09-01

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cyrus IMAP versions prior to 3.8.3 Cyrus IMAP versions 3.10.x prior to 3.10.0-rc1
Description The issue is related to a buffer overflow in memory, which can be exploited by sending several literals in a single command, potentially allowing a remote attacker to cause a denial of service. Authenticated attackers can cause unbounded memory allocation by sending many LITERALs in a single command.
Recommendations For Cyrus IMAP versions prior to 3.8.3, update to version 3.8.3 or later. For Cyrus IMAP versions 3.10.x prior to 3.10.0-rc1, update to version 3.10.0-rc1 or later. As a temporary workaround, consider restricting the number of LITERALs that can be sent in a single command to prevent unbounded memory allocation.

Exploit

Fix

DoS

Buffer Overflow

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:9195
BDU:2024-04474
CVE-2024-34055
DSA-5708-1
INFSA-2024_9195
OPENSUSE-SU-2025:14968-1
RHSA-2024:9195
RHSA-2024_9195
RLSA-2024:9195
USN-7224-1

Affected Products

Almalinux
Cyrus Imap
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu