Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-18928

Опубликовано: 15 нояб. 2019
Источник: debian
EPSS Низкий

Описание

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cyrus-imapdfixed3.0.12-1package
cyrus-imapdfixed3.0.8-6+deb10u3busterpackage

Примечания

  • https://github.com/cyrusimap/cyrus-imapd/commit/e675bf7b0e9c6e160516d274bffaec6f9dccaef7 (cyrus-imapd-3.0.12)

  • Fixed in 3.0.12 and 2.5.14 upstream

EPSS

Процентиль: 65%
0.005
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 7.4
redhat
около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
nvd
около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
github
больше 3 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

oracle-oval
около 5 лет назад

ELSA-2020-4655: cyrus-imapd security update (MODERATE)

EPSS

Процентиль: 65%
0.005
Низкий