CVE-2024-34055
published 2024-06-05CVE-2024-34055: Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single…
PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.84%
53.7th percentile
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | james_server | < 3.7.6 | 3.7.6 |
| apache | james_server | >= 3.8.0 < 3.8.2 | 3.8.2 |
| apache_software_foundation | apache_james_server | <= 3.7.5 | — |
| apache_software_foundation | apache_james_server | 3.8.0 – 3.8.1 | — |
| cyrusimap | cyrus_imap | < 3.8.3 | 3.8.3 |
| cyrusimap | cyrus_imap | — | — |
| debian | cyrus-imapd | < cyrus-imapd 3.6.1-4+deb12u2 (bookworm) | cyrus-imapd 3.6.1-4+deb12u2 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
ghsa6.5MEDIUM
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Cyrus IMAP Server vulnerabilities
vendor_ubuntu·2025-01-22·CVSS 9.8
CVE-2024-34055 [CRITICAL] Cyrus IMAP Server vulnerabilities
Title: Cyrus IMAP Server vulnerabilities
Summary: Several security issues were fixed in Cyrus IMAP Server.
It was discovered that non-authentication-related HTTP requests could be
interpreted in an authentication context by a Cyrus IMAP Server when
multiple requests arrived over the same connection. An unauthenticated
attacker could possibly use this issue to perform a privilege escalation
attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-18928)
Matthew Horsfall discovered that Cyrus IMAP Server utilized a poor string
hashing algorithm that could be abused to control where data was being
stored. An attacker could possibly use this issue to perform a denial of
service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2021-33582)
Damian Poddebniak discovere
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Spring Boot) — CVE-2023-34055
vendor_oracle·2024-10-15·CVSS 6.5
CVE-2023-34055 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Spring Boot) — CVE-2023-34055
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Spring Boot) vulnerability
CVE: CVE-2023-34055
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Boot) — CVE-2023-34055
vendor_oracle·2024-07-15·CVSS 6.5
CVE-2023-34055 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Boot) — CVE-2023-34055
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Boot) vulnerability
CVE: CVE-2023-34055
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Red Hat
cyrus-imapd: unbounded memory allocation by sending many LITERALs in a single command
vendor_redhat·2024-06-05·CVSS 6.5
CVE-2024-34055 [MEDIUM] CWE-119 cyrus-imapd: unbounded memory allocation by sending many LITERALs in a single command
cyrus-imapd: unbounded memory allocation by sending many LITERALs in a single command
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
A flaw was found in Cyrus IMAP before versions 3.8.3 and 3.10.x , and before 3.10.0-rc1. This flaw allows authenticated attackers to cause unbounded memory allocation by sending multiple LITERALs in a single command.
Package: cyrus-imapd (Red Hat Enterprise Linux 10) - Not affected
Package: cyrus-imapd (Red Hat Enterprise Linux 6) - Out of support scope
Package: cyrus-imapd (Red Hat Enterprise Linux 7) - Out of support scope
Package: cyrus-imapd (Red Hat Enterprise Linux 8) - Will not fix
Oracle
Oracle Oracle Communications Applications Risk Matrix: General (Spring Boot) — CVE-2023-34055
vendor_oracle·2024-04-15·CVSS 6.5
CVE-2023-34055 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: General (Spring Boot) — CVE-2023-34055
Oracle Oracle Communications Applications Risk Matrix: General (Spring Boot) vulnerability
CVE: CVE-2023-34055
CVSS: 6.5
Protocol: HTTPS
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Spring Boot) — CVE-2023-34055
vendor_oracle·2024-01-15·CVSS 6.5
CVE-2023-34055 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (Spring Boot) — CVE-2023-34055
Oracle Oracle Communications Risk Matrix: Configuration (Spring Boot) vulnerability
CVE: CVE-2023-34055
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Debian
CVE-2024-34055: cyrus-imapd - Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attack...
vendor_debian·2024·CVSS 6.5
CVE-2024-34055 [MEDIUM] CVE-2024-34055: cyrus-imapd - Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attack...
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
Scope: local
bookworm: resolved (fixed in 3.6.1-4+deb12u2)
bullseye: open
forky: resolved (fixed in 3.8.3-1)
sid: resolved (fixed in 3.8.3-1)
trixie: resolved (fixed in 3.8.3-1)
GHSA
Apache James vulnerable to denial of service through the use of IMAP literals
ghsa·2025-02-06·CVSS 6.5
CVE-2024-37358 [MEDIUM] CWE-20 Apache James vulnerable to denial of service through the use of IMAP literals
Apache James vulnerable to denial of service through the use of IMAP literals
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations
Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
OSV
Apache James vulnerable to denial of service through the use of IMAP literals
osv·2025-02-06·CVSS 6.5
CVE-2024-37358 [MEDIUM] Apache James vulnerable to denial of service through the use of IMAP literals
Apache James vulnerable to denial of service through the use of IMAP literals
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations
Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals.
OSV
cyrus-imapd vulnerabilities
osv·2025-01-22·CVSS 9.8
CVE-2019-18928 [CRITICAL] cyrus-imapd vulnerabilities
cyrus-imapd vulnerabilities
It was discovered that non-authentication-related HTTP requests could be
interpreted in an authentication context by a Cyrus IMAP Server when
multiple requests arrived over the same connection. An unauthenticated
attacker could possibly use this issue to perform a privilege escalation
attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-18928)
Matthew Horsfall discovered that Cyrus IMAP Server utilized a poor string
hashing algorithm that could be abused to control where data was being
stored. An attacker could possibly use this issue to perform a denial of
service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2021-33582)
Damian Poddebniak discovered that Cyrus IMAP Server could interpret
specially crafted commands to exploit a
GHSA
GHSA-crp5-539g-qwq6: Cyrus IMAP before 3
ghsa_unreviewed·2024-06-05
CVE-2024-34055 [MEDIUM] CWE-770 GHSA-crp5-539g-qwq6: Cyrus IMAP before 3
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
OSV
CVE-2024-34055: Cyrus IMAP before 3
osv·2024-06-05·CVSS 6.5
CVE-2024-34055 [MEDIUM] CVE-2024-34055: Cyrus IMAP before 3
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
No detection rules found.
No public exploits indexed.
https://github.com/cyrusimap/cyrus-imapd/commit/ef9e4e8314d6a06f2269af0ccf606894cc3fe489https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CJZQAE3XC2GBCE5KSTWJ5A6QYANFWGFB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVZHUZDU4MGTTZJRNACTMSKXLNMMRLJ6/https://www.cyrusimap.org/dev/imap/download/release-notes/3.10/x/3.10.0-rc1.htmlhttps://www.cyrusimap.org/imap/download/release-notes/3.8/x/3.8.3.htmlhttps://github.com/cyrusimap/cyrus-imapd/commit/ef9e4e8314d6a06f2269af0ccf606894cc3fe489https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CJZQAE3XC2GBCE5KSTWJ5A6QYANFWGFB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WVZHUZDU4MGTTZJRNACTMSKXLNMMRLJ6/https://www.cyrusimap.org/dev/imap/download/release-notes/3.10/x/3.10.0-rc1.htmlhttps://www.cyrusimap.org/imap/download/release-notes/3.8/x/3.8.3.html
2024-06-05
Published