Stack-based buffer overflow in Cyrus IMAP Server - CVE-2011-3208
Published: September 14, 2011 / Updated: August 19, 2020
Cyrus IMAP Server
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the split_wildmats function in nntpd.c in nntpd when processing a crafted NNTP command. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2011-3208
Sources
- http://asg.andrew.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=199
- http://asg.andrew.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&msg=200
- http://git.cyrusimap.org/cyrus-imapd/commit/?id=0f8f026699829b65733c3081657b24e2174f4f4d
- http://git.cyrusimap.org/cyrus-imapd/commit/?id=3244c18c928fa331f6927e2b8146abe90feafddd
- http://lists.opensuse.org/opensuse-updates/2011-09/msg00019.html
- http://secunia.com/advisories/45938
- http://secunia.com/advisories/45975
- http://secunia.com/advisories/46064
- http://securitytracker.com/id?1026031
- http://www.debian.org/security/2011/dsa-2318
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:149
- http://www.osvdb.org/75307
- http://www.redhat.com/support/errata/RHSA-2011-1317.html
- http://www.securityfocus.com/bid/49534
- https://bugzilla.redhat.com/show_bug.cgi?id=734926
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69679
- https://hermes.opensuse.org/messages/11723935