CVE-2004-1067

4 documents4 sources
Severity
10.0CRITICAL
EPSS
5.5%
top 9.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateApr 29

Description

Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDredhat/fedora_corecore_2.0, core_3.0+1

Also affects: Ubuntu Linux 4.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5mmh-rg36-rhxw: Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 22022-04-29
CVEList
CVE-2004-1067: Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 22004-12-10

📋Vendor Advisories

1
Ubuntu
cyrus21-imapd vulnerability2004-12-02
CVE-2004-1067 (CRITICAL CVSS 10) | Off-by-one error in the mysasl_cano | cvebase.io