Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Mageia: 2020-0010 Critical: Cyrus-IMAPD Access Control Issue

mageia
Calendar Grey January 5, 2020
Dist Mageia Esm H88
Revised dovecot packages address security vulnerability in Manjaro distribution concerning unauthorized access to email accounts.
Updated cyrus-imapd packages fix security vulnerability: It was discovered that the lmtpd component of the Cyrus IMAP server created mailboxes with administrator privileges if the...

Summary

Updated cyrus-imapd packages fix security vulnerability:
It was discovered that the lmtpd component of the Cyrus IMAP server created mailboxes with administrator privileges if the "fileinto" was used, bypassing ACL checks (CVE-2019-19783).

References

- https://bugs.mageia.org/show_bug.cgi?id=25913

- https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.12.html

- https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.13.html

-

- https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.15.html

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PHV3TUU53WCKJ3BBRK2EHAF44MSZEFK6/

- https://lists.debian.org/debian-security-announce/2019/msg00244.html

- https://www.cve.org/CVERecord?id=CVE-2019-19783

Resolution

SRPMS

- 7/core/cyrus-imapd-2.5.15-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0010.html
Type: security
CVE: CVE-2019-19783

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here