Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8076

Опубликовано: 18 июн. 2015
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cyrus-imapdWill not fix
Red Hat Enterprise Linux 6cyrus-imapdWill not fix
Red Hat Enterprise Linux 7cyrus-imapdWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1267869cyrus-imapd: Out of bounds heap read in index_urlfetch

EPSS

Процентиль: 87%
0.03261
Низкий

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

nvd
больше 10 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

debian
больше 10 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3. ...

github
больше 4 лет назад

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

fstec
больше 10 лет назад

Уязвимость почтового сервера Cyrus IMAP и операционных систем openSUSE и OpenSUSE Leap, позволяющая нарушителю получить конфиденциальную информацию или оказать другое воздействие

EPSS

Процентиль: 87%
0.03261
Низкий

3.5 Low

CVSS2