First published: Tue Aug 22 2017(Updated: )
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cyrus SASL | <=3.0.2 | |
Fedora | =26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12843 has a medium severity rating, as it allows remote authenticated users to write to arbitrary files.
To fix CVE-2017-12843, upgrade Cyrus IMAP to version 3.0.3 or later.
CVE-2017-12843 affects users of Cyrus IMAP versions prior to 3.0.3 and Fedora 26.
CVE-2017-12843 can be exploited using crafted SYNCAPPLY, SYNCGET, or SYNCRESTORE commands.
The impact of CVE-2017-12843 includes unauthorized file write access by remote authenticated users.