Back to Database
Status published
High
CVE-2011-3208
Stack-based buffer overflow in the split_wildmats function in nntpd.c in...
Vulnerability Description
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-3208
Credits & Attribution
No credits recorded in the NVD database.
References
- https://hermes.opensuse.org/messages/11723935
- http://secunia.com/advisories/46064
- http://git.cyrusimap.org/cyrus-imapd/commit/?id=3244c18c928fa331f6927e2b8146abe90feafddd
- http://www.securityfocus.com/bid/49534
- http://www.osvdb.org/75307
- http://lists.opensuse.org/opensuse-updates/2011-09/msg00019.html
- http://asg.andrew.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=200
- http://secunia.com/advisories/45975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69679
- http://asg.andrew.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=199
- http://www.redhat.com/support/errata/RHSA-2011-1317.html
- http://secunia.com/advisories/45938
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:149
- https://bugzilla.redhat.com/show_bug.cgi?id=734926
- http://www.debian.org/security/2011/dsa-2318
- http://git.cyrusimap.org/cyrus-imapd/commit/?id=0f8f026699829b65733c3081657b24e2174f4f4d
- http://securitytracker.com/id?1026031
More from cmu
View All →CVE-2022-31506
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path...
Critical
9.3
CVE-2014-7723
The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for...
Medium
5.4
CVE-2014-0027
The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local...
Low
3.3
CVE-2013-4122
Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle...
Medium
4.3
CVE-2011-3481
The index_get_ids function in index.c in imapd in Cyrus IMAP...
Medium
4.3
Affected Vendor
Affected Software
cyrus imap server
Vulnerable Versions:
0, 2.0.17, 2.1.16, 2.1.17, 2.1.18, 2.2.8, 2.2.9, 2.2.10, 2.2.11, 2.2.12, 2.2.13, 2.2.13p1, 2.2.14, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.3.10, 2.3.11, 2.3.12, 2.3.13, 2.3.14, 2.3.15, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9, 2.4.10
Timeline
Official Publish:
September 14th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.