Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11356

Опубликовано: 04 июн. 2019
Источник: redhat
CVSS3: 5.6
EPSS Средний

Описание

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

A flaw was found in the CalDAV feature in httpd in Cyrus IMAP. This flaw allows a remote attacker to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cyrus-imapdNot affected
Red Hat Enterprise Linux 6cyrus-imapdNot affected
Red Hat Enterprise Linux 7cyrus-imapdNot affected
Red Hat Enterprise Linux 8cyrus-imapdFixedRHSA-2019:177115.07.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1717828cyrus-imapd: buffer overflow in CalDAV request handling triggered by a long iCalendar property name

EPSS

Процентиль: 96%
0.2861
Средний

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 9.8
nvd
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

CVSS3: 9.8
debian
больше 6 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0 ...

CVSS3: 9.8
github
больше 3 лет назад

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

oracle-oval
больше 6 лет назад

ELSA-2019-1771: cyrus-imapd security update (IMPORTANT)

EPSS

Процентиль: 96%
0.2861
Средний

5.6 Medium

CVSS3