Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade perl-CyrusUpgrade cyrus-imapd-murderUpgrade cyrus-imapd-utilsUpgrade cyrus-imapd-perlUpgrade cyrus-imapdUpgrade cyrus-imapd-nntpUpgrade cyrus-imapd-devel | Dec 1, 2016 | Sep 14, 2011 |
| Gentoo Linux | — | Upgrade net-mail/cyrus-imapd. | Oct 30, 2017 | Sep 14, 2011 |
| Oracle_linux | — | Upgrade cyrus-imapd-perlUpgrade cyrus-imapd-develUpgrade cyrus-imapdUpgrade cyrus-imapd-utils | Oct 16, 2024 | Sep 14, 2011 |
| Suse | — | Upgrade sap-aio-releaseUpgrade cyrus-imapd-develUpgrade cyrus-imapdUpgrade perl-Cyrus-SIEVE-managesieveUpgrade perl-Cyrus-IMAP | Dec 12, 2013 | Sep 14, 2011 |
| Ubuntu | — | Upgrade cyrus-imapd-2.2 | Nov 19, 2024 | Sep 14, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub