This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Cmu First view 2011-05-23
Product Cyrus Imap Server Last view 2011-09-14
Version 2.3.0 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:cmu:cyrus_imap_server

Activity : Overall

Related : CVE

  Date Alert Description
4.3 2011-09-14 CVE-2011-3481

The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.

7.5 2011-09-14 CVE-2011-3208

Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.

5.1 2011-05-23 CVE-2011-1926

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-264 Permissions, Privileges, and Access Controls
50% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

Open Source Vulnerability Database (OSVDB)

id Description
75445 Cyrus IMAP Server imapd index.c index_get_ids Function References Header NULL...
75307 Cyrus IMAPd map/nntpd.c split_wildmats() Function NNTP Command Parsing Remote...
72186 Cyrus IMAP Server STARTTLS Arbitrary Plaintext Command Injection

OpenVAS Exploits

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2012-08-03 Name : Mandriva Update for cyrus-imapd MDVSA-2012:037 (cyrus-imapd)
File : nvt/gb_mandriva_MDVSA_2012_037.nasl
2012-07-30 Name : CentOS Update for cyrus-imapd CESA-2011:1508 centos5 x86_64
File : nvt/gb_CESA-2011_1508_cyrus-imapd_centos5_x86_64.nasl
2012-07-30 Name : CentOS Update for cyrus-imapd CESA-2011:1508 centos4 x86_64
File : nvt/gb_CESA-2011_1508_cyrus-imapd_centos4_x86_64.nasl
2012-07-30 Name : CentOS Update for cyrus-imapd CESA-2011:0859 centos4 x86_64
File : nvt/gb_CESA-2011_0859_cyrus-imapd_centos4_x86_64.nasl
2012-07-30 Name : CentOS Update for cyrus-imapd CESA-2011:1317 centos5 x86_64
File : nvt/gb_CESA-2011_1317_cyrus-imapd_centos5_x86_64.nasl
2012-07-30 Name : CentOS Update for cyrus-imapd CESA-2011:0859 centos5 x86_64
File : nvt/gb_CESA-2011_0859_cyrus-imapd_centos5_x86_64.nasl
2012-07-30 Name : CentOS Update for cyrus-imapd CESA-2011:1317 centos4 x86_64
File : nvt/gb_CESA-2011_1317_cyrus-imapd_centos4_x86_64.nasl
2012-04-02 Name : Fedora Update for cyrus-imapd FEDORA-2011-13832
File : nvt/gb_fedora_2011_13832_cyrus-imapd_fc16.nasl
2012-02-12 Name : Gentoo Security Advisory GLSA 201110-16 (Cyrus IMAP Server)
File : nvt/glsa_201110_16.nasl
2012-02-11 Name : Debian Security Advisory DSA 2377-1 (cyrus-imapd-2.2)
File : nvt/deb_2377_1.nasl
2011-12-02 Name : CentOS Update for cyrus-imapd CESA-2011:1508 centos4 i386
File : nvt/gb_CESA-2011_1508_cyrus-imapd_centos4_i386.nasl
2011-12-02 Name : CentOS Update for cyrus-imapd CESA-2011:1508 centos5 i386
File : nvt/gb_CESA-2011_1508_cyrus-imapd_centos5_i386.nasl
2011-12-02 Name : RedHat Update for cyrus-imapd RHSA-2011:1508-01
File : nvt/gb_RHSA-2011_1508-01_cyrus-imapd.nasl
2011-10-18 Name : Mandriva Update for squid MDVSA-2011:150 (squid)
File : nvt/gb_mandriva_MDVSA_2011_150.nasl
2011-10-18 Name : Mandriva Update for cyrus-imapd MDVSA-2011:149 (cyrus-imapd)
File : nvt/gb_mandriva_MDVSA_2011_149.nasl
2011-10-16 Name : Debian Security Advisory DSA 2318-1 (cyrus-imapd-2.2)
File : nvt/deb_2318_1.nasl
2011-10-14 Name : Fedora Update for cyrus-imapd FEDORA-2011-13869
File : nvt/gb_fedora_2011_13869_cyrus-imapd_fc14.nasl
2011-10-14 Name : Fedora Update for cyrus-imapd FEDORA-2011-13860
File : nvt/gb_fedora_2011_13860_cyrus-imapd_fc15.nasl
2011-09-23 Name : CentOS Update for cyrus-imapd CESA-2011:1317 centos5 i386
File : nvt/gb_CESA-2011_1317_cyrus-imapd_centos5_i386.nasl
2011-09-23 Name : RedHat Update for cyrus-imapd RHSA-2011:1317-01
File : nvt/gb_RHSA-2011_1317-01_cyrus-imapd.nasl
2011-09-23 Name : CentOS Update for cyrus-imapd CESA-2011:1317 centos4 i386
File : nvt/gb_CESA-2011_1317_cyrus-imapd_centos4_i386.nasl
2011-09-12 Name : Cyrus IMAP Server 'split_wildmats()' Remote Buffer Overflow Vulnerability
File : nvt/gb_cyrus_49534.nasl
2011-08-18 Name : CentOS Update for cyrus-imapd CESA-2011:0859 centos4 i386
File : nvt/gb_CESA-2011_0859_cyrus-imapd_centos4_i386.nasl
2011-08-09 Name : CentOS Update for cyrus-imapd CESA-2011:0859 centos5 i386
File : nvt/gb_CESA-2011_0859_cyrus-imapd_centos5_i386.nasl
2011-08-03 Name : Debian Security Advisory DSA 2258-1 (kolab-cyrus-imapd)
File : nvt/deb_2258_1.nasl

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2014-10-12 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2011-2.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_cyrus-imapd-111005.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_cyrus-imapd-110909.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_cyrus-imapd-110620.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_3_cyrus-imapd-111005.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_3_cyrus-imapd-110909.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_3_cyrus-imapd-110620.nasl - Type: ACT_GATHER_INFO
2013-09-04 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2011-27.nasl - Type: ACT_GATHER_INFO
2013-09-04 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2011-02.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2011-1508.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2011-1317.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2011-0859.nasl - Type: ACT_GATHER_INFO
2012-08-01 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20110919_cyrus_imapd_on_SL4_x.nasl - Type: ACT_GATHER_INFO
2012-08-01 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20111201_cyrus_imapd_on_SL4_x.nasl - Type: ACT_GATHER_INFO
2012-08-01 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20110608_cyrus_imapd_on_SL4_x.nasl - Type: ACT_GATHER_INFO
2012-03-26 Name: The remote Mandriva Linux host is missing one or more security updates.
File: mandriva_MDVSA-2012-037.nasl - Type: ACT_GATHER_INFO
2012-01-12 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2377.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_cyrus-imapd-7785.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_cyrus-imapd-7727.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_cyrus-imapd-7583.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_cyrus-imapd-111005.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_cyrus-imapd-110905.nasl - Type: ACT_GATHER_INFO
2011-12-02 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2011-1508.nasl - Type: ACT_GATHER_INFO
2011-12-02 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2011-1508.nasl - Type: ACT_GATHER_INFO
2011-10-24 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_cyrus-imapd-7786.nasl - Type: ACT_GATHER_INFO