Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11356

Опубликовано: 03 июн. 2019
Источник: debian

Описание

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cyrus-imapdfixed3.0.8-6package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1717828

  • https://github.com/cyrusimap/cyrus-imapd/commit/a5779db8163b99463e25e7c476f9cbba438b65f3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 5.6
redhat
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 9.8
nvd
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 9.8
github
больше 3 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

oracle-oval
больше 6 лет назад

ELSA-2019-1771: cyrus-imapd security update (IMPORTANT)