Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-1771

Опубликовано: 30 июл. 2019
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2019-1771: cyrus-imapd security update (IMPORTANT)

[3.0.7-15.1]

  • Resolves: #1718194 - don't overrun buffer when parsing strings with sscanf()

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

cyrus-imapd

3.0.7-15.el8_0.1

cyrus-imapd-utils

3.0.7-15.el8_0.1

cyrus-imapd-vzic

3.0.7-15.el8_0.1

Oracle Linux x86_64

cyrus-imapd

3.0.7-15.el8_0.1

cyrus-imapd-utils

3.0.7-15.el8_0.1

cyrus-imapd-vzic

3.0.7-15.el8_0.1

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 5.6
redhat
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 9.8
nvd
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 9.8
debian
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0 ...

CVSS3: 9.8
github
больше 3 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.