CVE-2001-1154: Medium severity carnegie mellon university cyrus imap server vulnerability
Published Aug 30, 2001
·Updated
Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.
Affected Software
4 affected components
Carnegie Mellon University Cyrus Imap Server=2.0.16
Carnegie Mellon University Cyrus Imap Server=2.0.15
Carnegie Mellon University Cyrus Imap Server=1.6.24
BSDI Bsd Os=4.2
Event History
Aug 30, 2001
CVE Published
04:00 AM
Mar 15, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1154?
CVE-2001-1154 is classified as a denial of service vulnerability that can disrupt the availability of the Cyrus IMAP server.
2
How do I fix CVE-2001-1154?
To mitigate CVE-2001-1154, upgrade to a later version of Cyrus IMAP server that addresses this vulnerability.
3
Which versions of Cyrus IMAP server are affected by CVE-2001-1154?
CVE-2001-1154 affects versions 1.6.24, 2.0.15, and 2.0.16 of the Cyrus IMAP server.
4
Is CVE-2001-1154 specific to certain operating systems?
Yes, CVE-2001-1154 specifically affects the Cyrus IMAP server running on BSDi 4.2.
5
Can CVE-2001-1154 be exploited remotely?
Yes, CVE-2001-1154 can be exploited remotely using PHP IMAP clients to cause the server to hang.