Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8076

Опубликовано: 18 июн. 2015
Источник: redhat
CVSS2: 3.5

Описание

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cyrus-imapdWill not fix
Red Hat Enterprise Linux 6cyrus-imapdWill not fix
Red Hat Enterprise Linux 7cyrus-imapdWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
Дефект:
CWE-122->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1267869cyrus-imapd: Out of bounds heap read in index_urlfetch

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

nvd
около 10 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

debian
около 10 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3. ...

github
больше 3 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

fstec
около 10 лет назад

Уязвимость почтового сервера Cyrus IMAP и операционных систем openSUSE и OpenSUSE Leap, позволяющая нарушителю получить конфиденциальную информацию или оказать другое воздействие

3.5 Low

CVSS2