First published: Thu Dec 03 2015(Updated: )
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =42.1 | |
SUSE Linux | =13.2 | |
Cyrus SASL | =2.3.0 | |
Cyrus SASL | =2.3.1 | |
Cyrus SASL | =2.3.2 | |
Cyrus SASL | =2.3.3 | |
Cyrus SASL | =2.3.4 | |
Cyrus SASL | =2.3.5 | |
Cyrus SASL | =2.3.6 | |
Cyrus SASL | =2.3.7 | |
Cyrus SASL | =2.3.8 | |
Cyrus SASL | =2.3.9 | |
Cyrus SASL | =2.3.10 | |
Cyrus SASL | =2.3.11 | |
Cyrus SASL | =2.3.12 | |
Cyrus SASL | =2.3.13 | |
Cyrus SASL | =2.3.14 | |
Cyrus SASL | =2.3.15 | |
Cyrus SASL | =2.3.16 | |
Cyrus SASL | =2.3.17 | |
Cyrus SASL | =2.3.18 | |
Cyrus SASL | =2.4.0 | |
Cyrus SASL | =2.4.1 | |
Cyrus SASL | =2.4.2 | |
Cyrus SASL | =2.4.3 | |
Cyrus SASL | =2.4.4 | |
Cyrus SASL | =2.4.5 | |
Cyrus SASL | =2.4.6 | |
Cyrus SASL | =2.4.7 | |
Cyrus SASL | =2.4.8 | |
Cyrus SASL | =2.4.9 | |
Cyrus SASL | =2.4.10 | |
Cyrus SASL | =2.4.11 | |
Cyrus SASL | =2.4.12 | |
Cyrus SASL | =2.4.13 | |
Cyrus SASL | =2.4.14 | |
Cyrus SASL | =2.4.15 | |
Cyrus SASL | =2.4.16 | |
Cyrus SASL | =2.4.17 | |
Cyrus SASL | =2.5.0 | |
Cyrus SASL | =2.5.1 | |
Cyrus SASL | =2.5.2 | |
Cyrus SASL | =2.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8076 is rated as medium severity due to the potential for information disclosure.
To fix CVE-2015-8076, update Cyrus IMAP to version 2.3.19, 2.4.18, or 2.5.4 or later.
CVE-2015-8076 affects Cyrus IMAP versions prior to 2.3.19, 2.4.18, and 2.5.4.
Yes, CVE-2015-8076 can be exploited by remote attackers through specific vectors related to the urlfetch range.
CVE-2015-8076 may lead to sensitive information leakage or unspecified impact due to out-of-bounds heap reads.