Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian: DSA-215-1 Critical: cyrus-imapd Buffer Overflow Remote Threat

debian
Calendar Grey December 23, 2002
Debian Logo
Critical vulnerability in Cyrus IMAP server enables remote exploitation. Upgrade recommended to secure your system.
There is a buffer overflow in the Cyrus IMAP server, which could be exploited by a remote attacker prior to logging in.

Summary

Timo Sirainen discovered a buffer overflow in the Cyrus IMAP server,
which could be exploited by a remote attacker prior to logging in. A
malicious user could craft a request to run commands on the server under
the UID and GID of the cyrus server.

For the current stable distribution (woody) this problem has been
fixed in version 1.5.19-9.1.

For the old stable distribution (potato) this problem has been fixed
in version 1.5.19-2.2.

For the current unstable distribution (sid) this problem has been
fixed in version 1.5.19-9.10. The cyrus21-imapd packages are not
vulnerable

We recommend that you upgrade your cyrus-imapd package.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to t...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: cyrus-imapd

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here