Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-34055

Опубликовано: 05 июн. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

A flaw was found in Cyrus IMAP before versions 3.8.3 and 3.10.x , and before 3.10.0-rc1. This flaw allows authenticated attackers to cause unbounded memory allocation by sending multiple LITERALs in a single command.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cyrus-imapdNot affected
Red Hat Enterprise Linux 6cyrus-imapdOut of support scope
Red Hat Enterprise Linux 7cyrus-imapdOut of support scope
Red Hat Enterprise Linux 8cyrus-imapdWill not fix
Red Hat Enterprise Linux 9cyrus-imapdFixedRHSA-2024:919512.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2290510cyrus-imapd: unbounded memory allocation by sending many LITERALs in a single command

EPSS

Процентиль: 68%
0.00571
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

CVSS3: 6.5
nvd
больше 1 года назад

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

CVSS3: 6.5
debian
больше 1 года назад

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authentica ...

rocky
8 месяцев назад

Moderate: cyrus-imapd security update

CVSS3: 6.5
github
больше 1 года назад

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

EPSS

Процентиль: 68%
0.00571
Низкий

6.5 Medium

CVSS3