Description
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.
Affected products
- carnegie_mellon_university / cyrus_imap_server2.1.7 – 2.1.7
- carnegie_mellon_university / cyrus_imap_server2.1.9 – 2.1.9
- carnegie_mellon_university / cyrus_imap_server2.1.10 – 2.1.10
- carnegie_mellon_university / cyrus_imap_server2.1.16 – 2.1.16
- carnegie_mellon_university / cyrus_imap_server2.2.0_alpha – 2.2.0_alpha
- carnegie_mellon_university / cyrus_imap_server2.2.1_beta – 2.2.1_beta
- carnegie_mellon_university / cyrus_imap_server2.2.2_beta – 2.2.2_beta
- carnegie_mellon_university / cyrus_imap_server2.2.3 – 2.2.3
- carnegie_mellon_university / cyrus_imap_server2.2.4 – 2.2.4
- carnegie_mellon_university / cyrus_imap_server2.2.5 – 2.2.5
- carnegie_mellon_university / cyrus_imap_server2.2.6 – 2.2.6
- carnegie_mellon_university / cyrus_imap_server2.2.7 – 2.2.7
- carnegie_mellon_university / cyrus_imap_server2.2.8 – 2.2.8
- conectiva / linux9.0 – 9.0
- conectiva / linux10.0 – 10.0
- openpkg / openpkgcurrent – current
- RedHat / fedora_corecore_2.0 – core_2.0
- RedHat / fedora_corecore_3.0 – core_3.0
- trustix / secure_linux2.0 – 2.0
- trustix / secure_linux2.1 – 2.1
- trustix / secure_linux2.2 – 2.2
- Ubuntu / ubuntu_linux4.1 – 4.1
- Ubuntu / ubuntu_linux4.1 – 4.1
References
- VENDOR_ADVISORYhttp://www.debian.org/security/2004/dsa-597
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/18199
- VENDOR_ADVISORYhttp://security.e-matters.de/advisories/152004.html
- MISChttp://asg.web.cmu.edu/cyrus/download/imapd/changes.html
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:139
- MAILING_LISThttp://marc.info/?l=bugtraq&m=110123023521619&w=2
- MISChttp://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=143
- VENDOR_ADVISORYhttp://secunia.com/advisories/13274/
- MISChttp://security.gentoo.org/glsa/glsa-200411-34.xml
- VENDOR_ADVISORYhttps://www.ubuntu.com/usn/usn-31-1/