Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian Bookworm: Critical DSA-5708-1 Update for cyrus-imapd DoS

debian
Calendar Grey June 11, 2024
Debian Logo
Investigate essential cyrus-imapd revisions within Debian addressing memory allocation vulnerabilities that could lead to potential denial of service exploits.
Damian Poddebniak discovered that the Cyrus IMAP server didn't restrict memory allocation for some command arguments which may result in denial of service

Summary

Damian Poddebniak discovered that the Cyrus IMAP server didn't restrict
memory allocation for some command arguments which may result in denial
of service. This update backports new config directives which allow to
configure limits, additional details can be found at:

https://www.cyrusimap.org/3.6/imap/download/release-notes/3.6/x/3.6.5.html

These changes are too intrusive to be backported to the version of
Cyrus in the oldstable distribution (bullseye). If the IMAP server is used
by untrusted users an update to Debian stable/bookworm is recommended.
In addition the version of cyrus-imapd in bullseye-backports will be
updated with a patch soon.

For the stable distribution (bookworm), this problem has been fixed in
version 3.6.1-4+deb12u2.

We recommend that you upgrade your cyrus-imapd packages.

For the detailed security status of cyrus-imapd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/cyrus-imapd

Further information about Debian Security ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: cyrus-imapd
CVE ID: CVE-2024-34055

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here