The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp1 | — | Upgrade cyrus-imapdUpgrade cyrus-imapd-utils | Nov 30, 2017 | Dec 3, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2015 |
| Suse | — | Upgrade perl-Cyrus-SIEVE-managesieveUpgrade cyrus-imapdUpgrade perl-Cyrus-IMAPUpgrade cyrus-imapd-devel | Jun 1, 2016 | Dec 3, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub