Buffer overflow in Cyrus IMAP Server - CVE-2019-11356
Published: June 9, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in a crafted HTTP PUT operation for an event with a long iCalendar property name. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
cyrus-imapd (Debian package)
cyrus-admin (Ubuntu package)
cyrus-caldav (Ubuntu package)
cyrus-common (Ubuntu package)
cyrus-imapd (Ubuntu package)
cyrus-replication (Ubuntu package)
cyrus-imapd
Red Hat Enterprise Linux for x86_64
Ubuntu
Fedora
How to mitigate CVE-2019-11356
cyrus-imapd (Debian package) - update to 2.5.10-3+deb9u1
cyrus-admin (Ubuntu package) - update to 2.5.10-3ubuntu1.1
cyrus-caldav (Ubuntu package) - update to 2.5.10-3ubuntu1.1
cyrus-common (Ubuntu package) - update to 2.5.10-3ubuntu1.1
cyrus-imapd (Ubuntu package) - update to 2.5.10-3ubuntu1.1
cyrus-replication (Ubuntu package) - update to 2.5.10-3ubuntu1.1
cyrus-imapd - addressed in versions 3.0.10-1.fc29, 3.0.10-1.fc30
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IGO43JS7IFDNITHXOOHOP6JHRKRDIYY6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PICSZDC3UGEUZ27VXGGM6OFI67D3KKLZ/
- https://www.cyrusimap.org/imap/download/release-notes/2.5/index.html
- https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.13.html
- https://www.cyrusimap.org/imap/download/release-notes/3.0/index.html
- https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.10.html
- https://www.debian.org/security/2019/dsa-4458