It was discovered that the Cyrus IMAP server was prone to a denial of service attack via input that is mishandled during hash-table interaction. Furthermore it allowed privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over . -------------------------------------------------------------------------Debian LTS Advisory DLA-3052-1
An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202006-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Cyrus IMAP Server: Access restriction bypass Date: June 15, 2020 Bugs: #703630 ID: 202006-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges. Background ========= The Cyrus IMAP Server is an efficient, highly-scalable IMAP e-mail server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-mail/cyrus-imapd < 3.0.13 > = 3.0.13 Description ========== An issue was discovered in Cyrus IMAP Server where sieve script uploading is excessively trusted. Impact ===== A user can use a sieve script to create any mailbox with administrator privileges. Workaround ========= Disable sieve script uploading until the upgrade is complete. Resolution ========= All Cyrus IMAP Server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-mail/cyrus-imapd-3.0.13" References ========= [ 1 ] CVE-2019-19783 https://nvd.nist.gov/vuln/detail/CVE-2019-19783 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202006-23 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and securityof our users' machines is of utmost importance to us. Any security concerns should be addressed to
The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2011-1508 https://access.redhat.com/errata/RHSA-2011:1508.html The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: cyrus-imapd-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.i386.rpm x86_64: cyrus-imapd-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.i386.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.x86_64.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.x86_64.rpm ia64: cyrus-imapd-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-devel-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-perl-2.3.7-12.0.1.el5_7.2.ia64.rpm cyrus-imapd-utils-2.3.7-12.0.1.el5_7.2.ia64.rpm SRPMS: https://oss.oracle.com:443/ol5/SRPMS-updates/cyrus-imapd-2.3.7-12.0.1.el5_7.2.src.rpm Description of changes: [2.3.7-12.0.1.el5_7.2] - Enabled lm_sensors-devel build dependency for x86 and x86_64 only [2.3.7-12.2] - fix CVE-2011-3481: NULL pointer dereference via crafted References header in email (#738391) - fix CVE-2011-3372: nntpd authentication bypass (#740822) . Oracle Linux 5 has been issued a significant security patch for cyrus, addressing severe vulnerabilities along with key rpm updates.. Oracle Linux,Cyrus IMAP,Security Update,ELSA-2011-1508,Threat Fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.