First published: Wed Jun 05 2024(Updated: )
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cyrus imap | <3.8.3 | 3.8.3 |
redhat/cyrus imap | <3.10.0 | 3.10.0 |
debian/cyrus-imapd | <=3.2.6-2+deb11u2<=3.2.6-2+deb11u4 | 3.6.1-4+deb12u3 3.6.1-4+deb12u2 3.10.1-1 |
Cyrus IMAP | <3.8.3 | |
Cyrus IMAP | =3.10.0-alpha0 | |
Cyrus IMAP | =3.10.0-beta1 | |
Cyrus IMAP | =3.10.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.