CVE-2024-34055
05.06.2024, 05:15
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cyrusimap | cyrus_imap | 𝑥 < 3.8.3 |
| cyrusimap | cyrus_imap | 3.10.0:alpha0 |
| cyrusimap | cyrus_imap | 3.10.0:beta1 |
| cyrusimap | cyrus_imap | 3.10.0:beta2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cyrus-imapd-2.4 |
| ||||||||||||||||
| cyrus-imapd |
|
References