LWN.net Logo

cyrus-imapd: denial of service

Package(s):cyrus-imapd CVE #(s):CVE-2011-3481
Created:October 24, 2011 Updated:March 23, 2012
Description: From the CVE entry:

The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.

Alerts:
Scientific Linux SL-cyru-20111201 2011-12-01
Oracle ELSA-2011-1508 2011-12-01
Oracle ELSA-2011-1508 2011-12-01
Oracle ELSA-2011-1508 2011-12-01
CentOS CESA-2011:1508 2011-12-01
CentOS CESA-2011:1508 2011-12-01
Red Hat RHSA-2011:1508-01 2011-12-01
openSUSE openSUSE-SU-2011:1170-1 2011-10-24
Gentoo 201110-16 2011-10-22
Debian DSA-2377-1 2012-01-01
Mandriva MDVSA-2012:037 2012-03-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds