Cyrus IMAP index_urlfetch Integer Overflow Vulnerability (CVE-2015-8078)
Cyrus IMAP index_urlfetch Integer Overflow Vulnerability (CVE-2015-8078)
Release date:
Updated on:
Affected Systems:
Cyrus Cyrus IMAP Server 2.5.6
Cyrus Cyrus IMAP Server 2.4.18
Cyrus Cyrus IMAP Server 2.3.19
Description:
CVE (CAN) ID: CVE-2015-8078
The Cyrus IMAP server is an email server developed by Carnegie Mellon University.
Cyrus IMAP 2.3.19, 2.4.18, 2.5.6, imap/index. the index_urlfetch function in c has the integer overflow vulnerability. Remote attackers can exploit this vulnerability to perform illegal operations by checking the urlfetch range and section_offset variable vectors.
<* Source: Cyrus
*>
Suggestion:
Vendor patch:
Cyrus
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://docs.cyrus.foundation/imap/release-notes/2.5/x/2.5.7.html
Https://cyrus.foundation/cyrus-imapd/commit? Id = 6fb6a272171f49c79ba6ab7c6403eb25b39ec1b2
This article permanently updates the link address: