THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-34055

Assignermitre
Reserved2024-04-30
Published2024-06-05
Updated2024-06-14

Description

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

References

https://github.com/cyrusimap/cyrus-imapd/commit/ef9e4e8314d6a06f2269af0ccf606894cc3fe489

https://www.cyrusimap.org/imap/download/release-notes/3.8/x/3.8.3.html

https://www.cyrusimap.org/dev/imap/download/release-notes/3.10/x/3.10.0-rc1.html

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CJZQAE3XC2GBCE5KSTWJ5A6QYANFWGFB/ (FEDORA-2024-f3e0255c75) vendor-advisory

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVZHUZDU4MGTTZJRNACTMSKXLNMMRLJ6/ (FEDORA-2024-123f2b3666) vendor-advisory

cve.org CVE-2024-34055

nvd.nist.gov CVE-2024-34055

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-34055
© Copyright 2024 THREATINT. Made in Cyprus with +