Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8,...
Vulnerability Description
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1011
Credits & Attribution
No credits recorded in the NVD database.
References
- http://security.e-matters.de/advisories/152004.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18198
- http://asg.web.cmu.edu/cyrus/download/imapd/changes.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:139
- http://marc.info/?l=bugtraq&m=110123023521619&w=2
- http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=143
- http://secunia.com/advisories/13274/
- http://security.gentoo.org/glsa/glsa-200411-34.xml
More from carnegie mellon university
View All →Affected Vendor
carnegie mellon university
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.