cbcvebase.
CVE-2019-11356
published 2019-06-03

CVE-2019-11356: The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.62%
93.9th percentile
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
cyrusimap2.5.0 – 2.5.12
cyrusimap3.0.0 – 3.0.9
debiancyrus-imapd< cyrus-imapd 3.0.8-6 (bookworm)cyrus-imapd 3.0.8-6 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/cyrusimap/cyrus-imapd/commit/a5779db8163b99463e25e7c476f9cbba438b65f3
commandHTTP PUT /caldav/<calendar>/<event> with iCalendar property name > 256 characters
  • Monitor HTTP PUT requests to CalDAV endpoints containing iCalendar property names exceeding 256 characters in length, which trigger a stack-based buffer overflow of the propname stack variable.
  • Alert on HTTP PUT operations targeting CalDAV feature endpoints in Cyrus IMAP httpd, particularly those with abnormally long iCalendar property names in the request body.
  • ·Successful remote code execution is considered difficult in practice; the attacker would need to embed shellcode within the iCalendar property name itself, which is an unusual and constrained attack vector.
  • ·Affected versions are Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9; fixed in 2.5.13 and 3.0.10. Red Hat Enterprise Linux 5, 6, and 7 are listed as not affected.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.