USN-7224-1: Cyrus IMAP Server vulnerabilities
It was discovered that non-authentication-related HTTP requests could be interpreted in an authentication context by a Cyrus IMAP Server when multiple requests arrived over the same connection. An unauthenticated attacker could possibly use this issue to perform a privilege escalation attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-18928) Matthew Horsfall discovered that Cyrus IMAP Server utilized a poor string hashing algorithm that could be abused to control where data was being stored. An attacker could possibly use this issue to perform a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-33582) Damian Poddebniak discovered that Cyrus IMAP Server could interpret specially crafted commands to exploit a memory issue. An authenticated attacker could possibly use this issue to perform a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-34055)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7224-1?
The severity of USN-7224-1 is considered to be high due to the potential for privilege escalation by an unauthenticated attacker.
How do I fix USN-7224-1?
To fix USN-7224-1, upgrade the affected packages to version 3.8.2-1ubuntu0.1~esm1 or the latest version available.
What systems are affected by USN-7224-1?
USN-7224-1 affects Ubuntu 24.04 systems with the specified vulnerable cyrus packages.
Is USN-7224-1 related to any specific vulnerabilities?
Yes, USN-7224-1 covers multiple CVEs, including CVE-2024-34055 and CVE-2021-33582, that contribute to the security concern.
What are the risks of not addressing USN-7224-1?
Failing to address USN-7224-1 may allow unauthorized users to escalate their privileges and potentially compromise the affected system.